Vulnerability Disclosure Policy
Sannvit, Inc. · Effective August 12, 2026 · Version 1.0
Sannvit builds evidence infrastructure whose entire value is that it can be trusted. If you find a security vulnerability in our software or our website, we want to hear about it, we will take it seriously, and we will not punish you for telling us.
1. Scope
This policy covers: our website; the Sannvit software we distribute (server components, SDKs, deployment configurations); and our build and release infrastructure to the extent you can observe it from the outside. Out of scope: systems belonging to our customers (a Sannvit deployment inside a customer's infrastructure is theirs — report issues in their deployment to them, and issues in our software to us); denial-of-service testing; social engineering of our people; and physical attacks.
2. How to report
Email brad@sannvit.com with: what you found, where, steps to reproduce, and your assessment of impact. We also serve this policy's essentials at /.well-known/security.txt (RFC 9116).
3. What we commit to
- Acknowledgment within 3 business days, and an assessment of the report within 10.
- A named human handles your report — evidence-honesty is our product, and that includes being straight with you about severity, timeline, and fix status.
- We will tell you when the issue is fixed, and, if you wish, credit you publicly once a fix has shipped. We do not currently pay bounties; we say so here rather than imply otherwise.
- If a vulnerability affects distributed customer deployments, we will notify affected customers with remediation guidance — coordinated with you on timing.
4. Safe harbor
If you make a good-faith effort to comply with this policy — testing only in scope, accessing no more data than needed to demonstrate the issue, not degrading service, not disclosing publicly before we've had a reasonable coordinated-disclosure window (we ask for 90 days, negotiable for severity) — then: we will not initiate legal action against you for your research, we consider it authorized under applicable anti-hacking laws (including the CFAA and Utah's computer-crimes statute), and we waive claims under our website terms' restrictions to the extent they would bar the research this policy invites. This safe harbor does not extend to actions materially outside this policy, and it cannot bind third parties.
5. Our side of the bargain
We run the same discipline internally: security findings in our own software are recorded, tracked to disposition, and — where our product is the right tool — sealed in our own ledger. A disclosure program without an internal discipline behind it is theater; ours has one.
6. Contact
Sannvit, Inc., 176 N 170 E, Orem, UT 84057 · brad@sannvit.com