SECURITY
Security and responsible disclosure
Security reporting and authorized security validation are separate activities. Neither a public website nor a disclosure channel creates blanket permission to test systems.
Reporting
If you believe you have discovered a security issue, use the security or contractual contact channel already provided in your Caelum relationship. Include the affected hostname or resource, observed behavior, timestamps, and enough reproduction detail for triage. Do not include unnecessary sensitive data.
Authorized testing
Active vulnerability scanning, penetration testing, load testing, tenant-boundary testing, credential attacks, destructive actions, or testing of third-party infrastructure require written authorization and explicit scope before execution.
An inquiry, public disclosure policy, or ordinary account access is not authorization.
Scope and evidence
Authorized testing should define targets, time boundaries, allowed and prohibited techniques, data-handling rules, escalation paths, evidence capture, and retest expectations. Unknown scope defaults to no active testing.
Response posture
Reports are evaluated against the affected system and current deployment. Remediation claims should be tied to a verifiable fix or retest rather than a generic acknowledgement.
