Effective date: September 23, 2026 · Last updated: September 23, 2026
Responsible Disclosure Policy
How to report security vulnerabilities in EventOS products and services.
Purpose
EventOS takes the security of our products and services seriously. Despite quality and security controls, vulnerabilities may still be discovered. This Responsible Disclosure Policy explains how to report security issues to us.
How to report
If you are a security researcher or ethical hacker and have found a vulnerability, abuse risk, or security-related bug in EventOS products, domains, or apps, email security@eventos.com.
Please include enough detail for us to reproduce the issue (steps, affected URL or component, screenshots or proof-of-concept where safe). Do not include sensitive personal data of third parties unless strictly necessary to demonstrate the issue.
Guidelines
- Act in good faith and avoid privacy violations, data destruction, or service disruption
- Do not access or modify data that is not yours beyond what is needed to demonstrate the issue
- Give us reasonable time to investigate and remediate before public disclosure
- Do not use social engineering against EventOS staff or customers as part of testing without prior written approval
Bug bounty
EventOS does not currently operate a paid bug bounty or reward program for vulnerability submissions. We still appreciate responsible reports and will acknowledge valid issues.
Contact
Security reports: security@eventos.com. For privacy concerns, use privacy@eventos.com or our Grievance Redressal Policy.