At Eve Security, protecting our customers' data, AI agents, and runtime environments is our highest priority. We welcome security researchers who help us identify vulnerabilities in our platform.
We believe coordinated vulnerability disclosure strengthens the security of the entire AI ecosystem and enables safer adoption of Agentic AI technologies.
Scope
The following assets are in scope:
- eve.security
- Web applications hosted under *.eve.security
- Public APIs operated by Eve Security
- Customer-facing SaaS services
Out of Scope
The following activities are not eligible:
- Denial of Service (DoS/DDoS)
- Social engineering of Eve employees
- Physical security testing
- Spam-related findings
- Previously reported vulnerabilities
- Automated scanning that negatively impacts service availability
- Vulnerabilities requiring unrealistic user interaction
Eligible Vulnerabilities
We are particularly interested in findings involving:
- Authentication and authorization bypass
- Privilege escalation
- Sensitive data exposure
- Cross-site scripting (XSS)
- Server-side request forgery (SSRF)
- Remote code execution
- Business logic vulnerabilities
- API security issues
- Multi-tenant isolation failures
- AI agent abuse or policy bypass
- Prompt injection leading to unauthorized actions
- Runtime control evasion techniques
- Data leakage through AI workflows
Safe Harbor
If you act in good faith and comply with this policy, Eve Security considers your research authorized and will not pursue legal action regarding your findings.
Please:
- Avoid accessing customer data.
- Stop testing immediately if sensitive information is exposed.
- Report vulnerabilities promptly.
- Give us reasonable time to investigate and remediate issues before public disclosure.
Rewards
Rewards are determined based on:
- Severity and impact
- Quality of report
- Reproducibility
- Novelty of the finding
How to Report
Submit reports to
Please include:
- Vulnerability description
- Reproduction steps
- Impact assessment
- Proof-of-concept screenshots or videos
- Suggested remediation (optional)
Hall of Fame
We recognize researchers who help improve the security of AI systems and protect our customers.