Back to all forms

Security

Security Report

Privately report suspected vulnerabilities or security concerns affecting ChemVault systems.

Active

Purpose

Security reports should be handled privately and responsibly.

  • Do not publicly disclose vulnerabilities before the ChemVault team has reviewed them.
  • Do not attack real user data, disrupt services, or upload malicious files.
  • You may submit reproduction steps, screenshots, logs, and impact notes.
  • High-risk vulnerabilities should be reported through a private contact channel.

Feedback intake

Security Report form

Complete the reply contact fields and the form prompts below. Required fields are marked with an asterisk.

9 required fields
Before submitting

Do not include passwords, API keys, payment details, private keys, or unrelated personal data. Redact sensitive text from screenshots, logs, and recordings.

Reply contact

How should ChemVault reply?

These fields are saved with the submission so an administrator can respond directly by email.

Use an inbox you can receive replies from. For TestFlight reports, use the invitation email if relevant.

Use a view-only link and remove private data before sharing.

Responsible disclosure agreement

Confirm that the report will stay private while the ChemVault team reviews it.

Feedback is submitted to the private ChemVault Forms queue. If you provide an email address, an administrator may reply by email.

Prompt guide

These prompts are included in the private submission record for administrator review and email follow-up.

  1. Reply contact: name, email, optional organization or role, and email reply consent
  2. Affected product
  3. Vulnerability type
  4. Severity estimate
  5. Description
  6. Steps to reproduce
  7. Impact
  8. Evidence
  9. Suggested fix
  10. Public disclosure status
  11. Responsible disclosure agreement
  12. Privacy confirmation
Submit Feedback