Responsible disclosure
Public intake processRequest a secure channel before sharing security details.
VerShep welcomes good-faith reports; the public website form is not an appropriate place for exploit details, credentials, private keys, customer data, or confidential evidence.
Request the channel
Email admin@vershep.com with the subject "Security report." Include only your contact information and the affected public VerShep surface. VerShep will provide an appropriate channel if the report is in scope.
Do not include in the public form
Do not submit vulnerability details, payloads, malware, private source, confidential findings, credentials, session data, private keys, personal data, or third-party information.
Current scope
The current public scope is the VerShep website and its public sample surfaces. CPF, DEP Early Access, customer environments, third-party services, social engineering, denial of service, and physical testing require separate written authorization.
Safe-harbor status
A formal vulnerability-disclosure and safe-harbor policy remains under legal review. Do not assume authorization beyond the written scope VerShep provides in response.