Last updated: January 2026
Quick Navigation
EvangelOS, Inc. ("EvangelOS," "we," "us," or "our") takes the security of our platform — and the trust churches place in us with member, child safety, and financial data — seriously. We welcome reports from independent security researchers who discover potential vulnerabilities in our products, and we're committed to working with the security community to verify, reproduce, and respond to legitimate reports.
This is a vulnerability disclosure program, not a paid bug bounty. We do not currently offer monetary rewards for reports, but we do offer public recognition (with your permission) and our sincere thanks — see Recognition below.
app.evangelos.app, api.evangelos.app, and subdomains)getevangelos.com)EvangelOS is a multi-tenant platform used by real churches, including data about children in their care. To keep testing safe for everyone:
Reports that involve real (non-test) organizations' or members' data, or that ignore these rules, may be declined and could fall outside the legal protections described in Safe Harbor below.
Email us at security@getevangelos.com with as much of the following as you can provide:
Please do not include real church, member, donor, or child data in your report — sanitized or synthetic examples are preferred. If you believe you've found an issue affecting real customer data, tell us that immediately without including the data itself, and we'll follow up securely.
EvangelOS considers security research conducted in good faith and in accordance with this policy to be authorized activity. We will not pursue civil action or file a complaint with law enforcement for accidental, good-faith violations of this policy, and we will not initiate legal action against you for security research performed consistent with this policy, including activity that might otherwise be restricted by our Terms of Service.
This safe harbor applies only to testing that stays within the scope and ground rules above. If a third party (for example, a subprocessor or hosting provider) initiates legal action related to your research, we will make it known that your actions were conducted under this policy, where accurate.
When you submit a report in good faith, here's what to expect:
Remediation timelines depend on severity: critical issues are prioritized for immediate action, while lower-severity findings are scheduled into our normal engineering work. We'll let you know once a fix has shipped.
We don't currently offer a paid bug bounty, but with your permission, we're glad to publicly thank researchers who submit valid, in-scope reports. Let us know in your report if you'd like to be credited and how you'd like your name or handle to appear.
Contact us at security@getevangelos.com.
This policy is effective as of January 2026 and may be updated from time to time.