Responsible disclosure

Responsible Disclosure / Vulnerability Disclosure

Report potential security vulnerabilities in a safe, accountable way. Use the dedicated security channel and follow the guardrails below to avoid harm to Verbum customers, systems, providers or data.

Responsible disclosure

Report safely, minimize impact and stop when risk is confirmed.

This policy explains how researchers, customers and procurement teams can report suspected vulnerabilities without harming Verbum customers, systems, providers or data. Use only your own authorized accounts, keep testing minimal and avoid activity that could affect availability, confidentiality or integrity.

Scope

What Verbum can review

  • Public pages and documented public flows on vrbm.app.
  • Authentication and authorization behavior visible to your own legitimate account.
  • Security-related controls described in the public Security and Trust Center pages.
  • Tenant-level boundaries represented only in your own test account or explicitly authorized workspace.

Permitted testing

  • Validate publicly documented behavior and access controls without changing production data.
  • Document suspected rate limiting, error handling or transport security issues without high-volume testing.
  • Check role boundaries and approval flow behavior only in accounts and workspaces you are authorized to use.
  • Verify tenant isolation only with your own test data and stop immediately if third-party data appears.

Out of scope and prohibited testing

  • Destructive testing, unsafe payloads, data modification, malware, cryptomining, persistence or backdoors.
  • Social engineering, phishing, spam, abuse of messaging channels or contact with Verbum customers.
  • DDoS, stress testing, traffic spikes, resource exhaustion or activity that could affect availability.
  • Brute force, credential stuffing, password spraying or automated authentication abuse.
  • Accessing, copying, collecting, scraping or exfiltrating customer, employee or third-party data.
  • Physical attacks, office/site testing, device theft or attempts to access non-public facilities.
  • Testing third-party providers, payment flows or integrations without separate authorization from that provider.

Safe harbor status

This public page is not a standalone legal safe harbor, waiver or authorization to access systems beyond the scope described here. Good-faith reports that follow this policy are appreciated, but researchers remain responsible for complying with applicable law and obtaining any authorization required for their testing.

What not to do

  • Do not access, copy, modify or delete customer, employee or third-party data.
  • Do not continue testing after confirming a vulnerability or crossing a tenant boundary.
  • Do not run scanners or automated tests that create volume, noise, spam or availability risk.
  • Do not publicly disclose details before Verbum has had a reasonable opportunity to review and remediate.

How to report responsibly

Report with reproducible details

What to include

  • Affected URL, route, feature or public flow.
  • Clear steps to reproduce using safe, non-destructive test data.
  • Expected behavior, observed behavior and potential impact.
  • Screenshots, screen recordings or logs with secrets and personal data removed.
  • Your preferred contact details for follow-up questions.

Non-destructive testing guardrails

Do not attempt to impact service availability, degrade message delivery, force account/session state changes, copy third-party data or continue testing after a boundary issue is confirmed. Use controlled test data and your own explicitly authorized accounts.

  • This is not a paid bug bounty program unless Verbum separately publishes a written bounty policy.
  • Reports may be submitted in English or Portuguese.
  • Verbum reviews reports based on risk, reproducibility and available context. No response SLA is promised by this public policy.

Response expectations

What happens after a report

  • Verbum reviews reports based on risk, reproducibility and available context.
  • We may ask for clarification, affected URLs, screenshots or additional reproduction details.
  • This public policy does not promise a response SLA, remediation timeline or paid reward.
  • Customer security review materials remain available through qualified procurement or security review.

Legal and security contact

Report a security concern or request security review.

Use the dedicated security channel for vulnerability reports. Procurement and customer security review requests can use the contact form so the request is routed with the right context.