Purpose
Security reports should be handled privately and responsibly.
- Do not publicly disclose vulnerabilities before the ChemVault team has reviewed them.
- Do not attack real user data, disrupt services, or upload malicious files.
- You may submit reproduction steps, screenshots, logs, and impact notes.
- High-risk vulnerabilities should be reported through a private contact channel.
Feedback intake
Security Report form
Complete the reply contact fields and the form prompts below. Required fields are marked with an asterisk.
Prompt guide
These prompts are included in the private submission record for administrator review and email follow-up.
- Reply contact: name, email, optional organization or role, and email reply consent
- Affected product
- Vulnerability type
- Severity estimate
- Description
- Steps to reproduce
- Impact
- Evidence
- Suggested fix
- Public disclosure status
- Responsible disclosure agreement
- Privacy confirmation