# Security and vulnerability disclosure.

This page explains how to report a Viorant vulnerability privately, which systems are in scope, the safe-harbor terms for good-faith research, and the current security boundaries of Viorant products and releases.

Last updated: August 2026

01

## Reporting a Vulnerability

Email security@viorant.ai. Please report privately and give us a chance to fix the issue before it is disclosed publicly.

We acknowledge every report within three business days and will tell you whether we consider it in scope, what we intend to do, and roughly when. If a report is not in scope we will say so plainly rather than leave it unanswered.

Viorant does not currently run a paid bug bounty. We credit researchers who ask to be credited.

02

## What to Include

A useful report lets us reproduce the issue without guesswork:

- The affected surface: the website, the Control Plane API, or the Viorant Hub desktop application, including its version.

- Steps to reproduce, with the requests, payloads, or files involved.

- What an attacker gains: the concrete impact, not only the class of bug.

- Any proof-of-concept code, kept to the minimum needed to demonstrate the issue.

03

## In Scope

- viorant.ai and its subdomains.

- The Viorant Control Plane API.

- The Viorant Hub desktop application for macOS and Windows.

- Release and update integrity, including signing, notarization, and the auto-update path.

04

## Out of Scope

The following are not eligible, either because they are outside our control or because they do not describe a real attack:

- Denial of service, volumetric testing, or automated scanning that degrades service for others.

- Social engineering of Viorant staff, customers, or vendors, and physical attacks.

- Vulnerabilities in third-party services we consume, which should be reported to those vendors.

- Missing hardening headers, weak ciphers, or scanner output with no demonstrated impact.

- Findings that require a compromised operating system, a rooted device, or an attacker who already has local access to the user account.

05

## Safe Harbor

If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research.

Good faith means you avoid privacy violations, data destruction, and service degradation; you access only accounts and data you own or have permission to test; you stop as soon as you have demonstrated the issue; and you do not use the finding for any purpose beyond the report.

If a third party brings action against you for research conducted under this policy, we will make it known that your work was authorized.

06

## Coordinated Disclosure

We ask for 90 days from acknowledgment before public disclosure, and we will usually be finished well before that. If a fix will take longer we will tell you why and agree a date with you rather than let the deadline pass in silence.

When a fix ships we will confirm it to you and, where the issue affected users, describe it in the release notes.

07

## Where Your Data Can Travel

Some security properties are decisions about structure rather than controls added afterward. Three shape most of the answer:

- Provider API keys are stored in your operating system keychain, scoped per user, and are never proxied through Viorant.

- Viorant is not on your model execution path. The Hub builds and prepares artifacts; your application calls your model provider directly.

- Authoring and testing run on your machine. The Hub works offline, and cloud connectivity is enrichment rather than a dependency.

How we handle the information we do collect is described in the Privacy Policy.

08

## Release Integrity

macOS builds are signed with an Apple Developer ID certificate and notarized by Apple. Windows builds are code-signed. Published releases carry checksums, and the auto-update path verifies what it stages before installing it.

If you obtained Viorant Hub anywhere other than viorant.ai or dl.viorant.ai, we cannot vouch for it.

09

## Supply Chain

Dependency scanning and secret scanning run in continuous integration across our repositories, and a failing scan blocks a release build rather than warning beside it.

Dependencies are pinned to immutable release tags so that a build cannot silently change underneath a published version.

## On this page

- [01 Reporting a Vulnerability](#reporting)

- [02 What to Include](#what-to-include)

- [03 In Scope](#scope)

- [04 Out of Scope](#out-of-scope)

- [05 Safe Harbor](#safe-harbor)

- [06 Coordinated Disclosure](#disclosure)

- [07 Where Your Data Can Travel](#architecture)

- [08 Release Integrity](#release-integrity)

- [09 Supply Chain](#supply-chain)

## Found something?

Report it privately and we will work it with you.

[security@viorant.ai ->](mailto:security@viorant.ai)

We acknowledge every report within three business days.

## Build better. Ship with confidence. Download Hub today.

[Download the Hub](/download)

macOS Windows Linux
