Skip to content

Trust & Legal

Report a vulnerability

Instructions for reporting a suspected vulnerability in an Endeavor Elements-operated public service.

Owner:
Yves Remmler
Last reviewed:
August 26, 2026

Report securely

Email support@endeavor-elements.com with a description, reproduction steps, affected service, potential impact, and a safe way to contact you.

We aim to acknowledge a report within five business days.

Scope

Public services operated by Endeavor Elements are in scope. Third-party services and systems not operated by Endeavor Elements are outside this policy.

Research rules

  • Do not disrupt services or degrade availability.
  • Do not use social engineering or physical attacks.
  • Do not access, modify, retain, or disclose another person's or customer's data.
  • Stop testing and report promptly if you encounter sensitive information.
  • Do not publicly disclose a suspected vulnerability before coordinating with Endeavor Elements.

Safe harbor and coordination

Endeavor Elements will not pursue legal action against good-faith research conducted in compliance with this policy. We will coordinate remediation communications and any public disclosure with the reporter.