Vulnerability Disclosure Policy

Last updated: January 2026

Quick Navigation

Our Commitment Scope Ground Rules How to Report Safe Harbor Our Response & Timelines Recognition Contact

Our Commitment to Security

EvangelOS, Inc. ("EvangelOS," "we," "us," or "our") takes the security of our platform — and the trust churches place in us with member, child safety, and financial data — seriously. We welcome reports from independent security researchers who discover potential vulnerabilities in our products, and we're committed to working with the security community to verify, reproduce, and respond to legitimate reports.

This is a vulnerability disclosure program, not a paid bug bounty. We do not currently offer monetary rewards for reports, but we do offer public recognition (with your permission) and our sincere thanks — see Recognition below.

Scope

In Scope

  • The EvangelOS web application and API (app.evangelos.app, api.evangelos.app, and subdomains)
  • The EvangelOS mobile apps (iOS and Android)
  • This marketing website (getevangelos.com)

Out of Scope

  • Denial-of-service (DoS/DDoS) testing, load testing, or spam/volumetric testing of any kind
  • Social engineering, phishing, or physical attacks against EvangelOS staff, contractors, or offices
  • Third-party services we integrate with but do not operate (Stripe, SendGrid, Telnyx, WorkOS, MinistrySafe/Vetty, Google Cloud Platform, Datadog, and other subprocessors listed on our Trust Center) — please report those directly to the vendor
  • Findings from automated scanners without a demonstrated, working proof of concept
  • Reports requiring physical access to a device, or that rely on a compromised/rooted device or browser
  • Issues that only affect users of unsupported/out-of-date browsers
  • Missing security headers, cookie flags, or other best-practice observations with no demonstrated impact
  • Any access to, modification of, or exfiltration of data belonging to a real church organization, member, donor, or any minor's data — see the ground rules below

Ground Rules for Testing

EvangelOS is a multi-tenant platform used by real churches, including data about children in their care. To keep testing safe for everyone:

  • Only test using your own account. Sign up for your own free/trial organization and confine all testing to data you created yourself. Never attempt to access, view, or modify another organization's or another individual's data — including other tenants' members, donations, or children's records — even if a vulnerability appears to make it possible.
  • Stop and report as soon as you've confirmed impact. The moment you've established that a vulnerability exists (e.g., a single record from another tenant, or a proof-of-concept request), stop testing and send us a report rather than continuing to explore or exfiltrate further data.
  • No destructive testing. Don't run anything intended to degrade, delete, or corrupt production data or service availability.
  • Give us a reasonable time to respond before disclosing anything publicly — see Our Response & Timelines.

Reports that involve real (non-test) organizations' or members' data, or that ignore these rules, may be declined and could fall outside the legal protections described in Safe Harbor below.

How to Report a Vulnerability

Email us at security@getevangelos.com with as much of the following as you can provide:

  • A clear description of the vulnerability and its potential impact
  • Step-by-step instructions to reproduce it, including the affected URL(s) or endpoint(s)
  • Any proof-of-concept code, screenshots, or request/response captures
  • The test account/organization you used (never a real customer's)
  • Your name and, if you'd like credit, how you'd like to be identified

Please do not include real church, member, donor, or child data in your report — sanitized or synthetic examples are preferred. If you believe you've found an issue affecting real customer data, tell us that immediately without including the data itself, and we'll follow up securely.

Safe Harbor

EvangelOS considers security research conducted in good faith and in accordance with this policy to be authorized activity. We will not pursue civil action or file a complaint with law enforcement for accidental, good-faith violations of this policy, and we will not initiate legal action against you for security research performed consistent with this policy, including activity that might otherwise be restricted by our Terms of Service.

This safe harbor applies only to testing that stays within the scope and ground rules above. If a third party (for example, a subprocessor or hosting provider) initiates legal action related to your research, we will make it known that your actions were conducted under this policy, where accurate.

Our Response & Timelines

When you submit a report in good faith, here's what to expect:

  • Acknowledgment — within 3 business days of your report
  • Triage & validation — within 10 business days, with an initial severity assessment
  • Status updates — periodically as we work through remediation, especially for higher-severity findings
  • Coordinated disclosure — we ask for up to 90 days from acknowledgment before any public disclosure, so we have time to remediate; we're happy to discuss a different timeline for well-documented, high-severity reports

Remediation timelines depend on severity: critical issues are prioritized for immediate action, while lower-severity findings are scheduled into our normal engineering work. We'll let you know once a fix has shipped.

Recognition

We don't currently offer a paid bug bounty, but with your permission, we're glad to publicly thank researchers who submit valid, in-scope reports. Let us know in your report if you'd like to be credited and how you'd like your name or handle to appear.

Questions or Reports

Contact us at security@getevangelos.com.

This policy is effective as of January 2026 and may be updated from time to time.