Vulnerability Disclosure
We welcome good-faith reports of security weaknesses affecting Account:dir. Email security@accountdir.com with a concise description, affected URL or feature, reproduction steps, expected and observed behavior, and a safe way to contact you. Do not include passwords, recovery keys, decrypted vault data, or other users' personal information in a report. If sensitive material was inadvertently accessed, stop, secure it, and tell us what happened without sharing more than necessary.
In scope
Security issues in accountdir.com and application features directly operated by EV Time LLC are in scope, provided testing uses accounts you own or have explicit permission to use. Third-party providers and infrastructure that we do not control are outside the scope of this policy; follow their own reporting policies.
Good-faith testing
Keep testing limited to the minimum necessary to demonstrate a vulnerability. Do not access, alter, download, or disclose another user's data; do not perform denial-of-service attacks, social engineering, spam, destructive tests, physical attacks, or automated high-volume scanning. Do not exploit a vulnerability beyond what is needed to confirm it. Give us a reasonable opportunity to investigate and address a report before public disclosure, and coordinate any disclosure with us.
We will acknowledge reports when reasonably possible, investigate credible findings, and work with you on next steps. We do not promise a fixed response or remediation deadline, and this policy does not offer a bounty.
Authorization
If you act in good faith and stay within this policy's scope, we will not initiate legal action against you for that authorized research. This statement does not authorize testing of third-party systems and does not bind others or override applicable law. If you are uncertain whether a technique is in scope, ask security@accountdir.com before using it.