Security & Responsible Disclosure
Ovyero welcomes security research. If you find a vulnerability in our service, please tell us before disclosing publicly. We do not pursue legal action against researchers acting in good faith.
Scope (in-scope)
ovyero.visnryentertainment.com and all subpaths
aios.visnryentertainment.com and all subpaths (when live)
- The published CLI tarball at
/package.tgz
- The hash-chain verifier and audit ledger format
Out of scope
- Findings against third-party infrastructure we don't control (Railway, Stripe, Resend), please report those to the respective vendors
- Denial-of-service via volumetric flooding
- Social engineering of the founder or future staff
- Physical attacks against Railway data centers
- Self-XSS that requires the victim to paste payloads into a console
Bug bounty
We do not currently run a paid bug bounty (target: 2026 Q4). We do offer public acknowledgment in the Hall of Fame below for researchers who follow responsible disclosure. We're also happy to provide a reference for your work to future employers when appropriate.
What we ask
- Give us a reasonable window (30 days default) to remediate before public disclosure
- Don't access, modify, or destroy customer data, proof-of-concept against your own Ovyero account is fine
- Don't run automated scans that degrade service for other customers
- Tell us how to reproduce the issue and what impact you observed
Safe harbor
If you act in good faith under this policy, we will not pursue legal action against you, even if your testing causes inadvertent disruption. We will work with you to coordinate disclosure.
Hall of Fame
Researchers who have helped harden Ovyero:
- (awaiting first external report)
Policy version: 2026-05-18. Reviewed annually.