Caelum Corp
Inside↗

SECURITY

Security and responsible disclosure

Security reporting and authorized security validation are separate activities. Neither a public website nor a disclosure channel creates blanket permission to test systems.

Reporting

If you believe you have discovered a security issue, use the security or contractual contact channel already provided in your Caelum relationship. Include the affected hostname or resource, observed behavior, timestamps, and enough reproduction detail for triage. Do not include unnecessary sensitive data.

Authorized testing

Active vulnerability scanning, penetration testing, load testing, tenant-boundary testing, credential attacks, destructive actions, or testing of third-party infrastructure require written authorization and explicit scope before execution.

An inquiry, public disclosure policy, or ordinary account access is not authorization.

Scope and evidence

Authorized testing should define targets, time boundaries, allowed and prohibited techniques, data-handling rules, escalation paths, evidence capture, and retest expectations. Unknown scope defaults to no active testing.

Response posture

Reports are evaluated against the affected system and current deployment. Remediation claims should be tied to a verifiable fix or retest rather than a generic acknowledgement.