Authorised use only
Use the website and email channel for lawful, genuine communication. Do not impersonate another person, send malicious or deceptive material, misuse someone else’s information, or interfere with access to the service.
SOVRAX’s cybersecurity activities do not authorise visitors to test this website, its hosting platform, clients or connected systems. Written permission must identify the system owner, assets, methods, timing and boundaries before any security assessment begins.
Activities outside permitted use
Without explicit authorisation, do not:
- Attempt to bypass authentication, access restrictions or licensing controls.
- Run intrusive scans, exploit a weakness, elevate privileges or access another person’s data.
- Perform denial-of-service testing, destructive actions, persistence, malware delivery or credential attacks.
- Extract or publish confidential information, or use automated requests in a way that disrupts the service.
- Use the enquiry address for harassment, spam, impersonation or unsolicited sensitive material.
Report a suspected vulnerability
If you notice a possible issue during ordinary use, stop before accessing additional information or changing any data. Email contact@sovrax.io with “Security report” in the subject. The corporate mailbox is not an emergency-response service, and this notice does not promise a response deadline.
- Identify the affected page or resource and the approximate time you noticed the issue.
- Describe the observed behaviour and expected behaviour clearly.
- Include only minimal, non-sensitive evidence. Redact personal data, credentials and tokens.
- If evidence is sensitive, first ask for an agreed secure channel rather than attaching it.
Disclosure and investigation limits
Avoid public disclosure of information that would expose users or systems while a report is being assessed. Keep evidence limited to what is necessary and do not retain or distribute other people’s data. SOVRAX may need the relevant provider or system owner to investigate an issue outside its control.
This notice is not a bug-bounty programme, a reward promise, testing authorisation or a legal safe-harbour commitment. Do not assume that a report retroactively authorises testing. Any further validation must have explicit written scope and permission.
Misuse, restrictions and privacy
Access may be restricted through appropriate service or hosting controls where needed to protect availability or investigate misuse. Where legally required, relevant information may be provided to the appropriate authority. This does not remove rights protected by applicable law.
Security reports may contain personal information. The website privacy policy applies to the email channel; a separate confidential handling arrangement can be agreed where necessary.