Security

Vulnerability Disclosure Policy

Last updated: August 18, 2026

We welcome reports from security researchers. This page describes how to report a vulnerability in Vaila and what you can expect from us.

Reporting a vulnerability

Email support@vailaapp.com with enough detail to reproduce the issue — the affected URL or endpoint, the steps you took, and what you observed. You do not need to be a Vaila user to report something. We aim to acknowledge reports within 5 business days.

What's in scope

  • The Vaila web app and marketing site
  • The Vaila API
  • The Vaila iOS app

What's out of scope

  • Findings against our service providers' own infrastructure — report those to the provider
  • Reports generated solely by automated scanners with no demonstrated impact
  • Social engineering of our team or our users, and physical attacks
  • Denial-of-service testing, load testing, or anything that degrades the service for other people

Testing rules

Please test only against accounts and data you control. Do not access, modify, retain, or exfiltrate other people's data — if you encounter someone else's personal information, stop, and tell us what you found rather than collecting more. Do not run automated scans heavy enough to affect availability.

Safe harbour

If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research, and we'll treat your report as authorised access. If a third party brings action against you for research conducted under this policy, we'll make that authorisation clear. Working within this policy does not waive obligations you may have to anyone other than Vaila.

Disclosure

Please give us a reasonable window to remediate before disclosing publicly, and coordinate timing with us. We do not currently run a paid bug-bounty programme, so we can't offer a reward, but we're glad to credit you when a report leads to a fix.

Contact

support@vailaapp.com — machine-readable contact at /.well-known/security.txt