legal

Vulnerability Disclosure Policy

Last updated: 2026-08-16. Governing law: Israel.

Coordinated Vulnerability Disclosure Policy

EyalSec sells security tooling. It would be absurd to make it hard to report a security problem in it, so this page sets out how to do that, what we commit to in return, and the safe harbour that protects you for good-faith research.

Published by Eyal Gabay, trading as "EyalSec", sole proprietor (osek murshe) no. 211868450, Israel.

Report to: security@eyalsec.com

This policy is referenced by the Terms of Service (/legal/terms, Section 9(d)), the Acceptable Use Policy (/legal/aup, Sections 5 and 8), and the security page (/legal/security).


1. Scope

In scope:

Out of scope:

A note on es-chromium. es-chromium is a security monitoring and testing instrument, not a hardened consumer browser, and we say so in Section 10(a) of the Terms. A report that it does not match the defensive posture of a mainstream consumer browser is a known and disclosed characteristic, not a vulnerability. A specific, exploitable flaw in our own functionality is in scope and we want it.

2. How to report

Email security@eyalsec.com with:

English or Hebrew are both fine. If you want to encrypt your report, say so and we will arrange a key.

3. Rules for testing

To stay inside the safe harbour in Section 5, you must:

4. What we commit to

| Stage | Our commitment | |-------|----------------| | Acknowledgement | Within 3 business days of your report reaching us. | | Initial assessment | Within 10 business days: whether we accept it, our severity assessment, and our intended course. | | Progress updates | At least every 14 days while the issue is open. | | Fix target | Critical and high severity: as fast as we can, targeting 30 days. Medium and low: with the next reasonable release. | | Notification | We tell you when it is fixed, and we tell affected customers where the issue warrants it. | | Credit | Public credit if you want it, anonymity if you prefer. Your choice, and we will ask before naming you. |

We do not currently run a paid bug bounty, and we will not pretend otherwise. There is no monetary reward. We are grateful anyway, and we credit properly.

5. Safe harbour

If you make a good-faith effort to comply with this policy, we will treat your research as authorized. Specifically, for such research:

This safe harbour covers only your dealings with EyalSec's own systems and software. It cannot and does not authorize you to test a customer's systems, or a third party's, and it does not waive any third party's rights. It also does not apply if you deliberately access or exfiltrate data that is not yours, extort us, or publish before the coordination period in Section 6.

If you are unsure whether something is in bounds, ask first at security@eyalsec.com. We would much rather answer a question than argue afterwards.

6. Coordinated disclosure

7. Our own vulnerability handling

8. Reporting something other than a vulnerability

9. Changes

We may update this policy. The version in force when you report is the one that applies to your report.

EyalSec Pricing Docs Security Login Book a live demo