Trust & Legal
Report a vulnerability
Instructions for reporting a suspected vulnerability in an Endeavor Elements-operated public service.
- Owner:
- Yves Remmler
- Last reviewed:
- August 26, 2026
Report securely
Email support@endeavor-elements.com with a description, reproduction steps, affected service, potential impact, and a safe way to contact you.
We aim to acknowledge a report within five business days.
Scope
Public services operated by Endeavor Elements are in scope. Third-party services and systems not operated by Endeavor Elements are outside this policy.
Research rules
- Do not disrupt services or degrade availability.
- Do not use social engineering or physical attacks.
- Do not access, modify, retain, or disclose another person's or customer's data.
- Stop testing and report promptly if you encounter sensitive information.
- Do not publicly disclose a suspected vulnerability before coordinating with Endeavor Elements.
Safe harbor and coordination
Endeavor Elements will not pursue legal action against good-faith research conducted in compliance with this policy. We will coordinate remediation communications and any public disclosure with the reporter.