No bounty or SLA
The demo makes no promise of a reward, response time, coordinated disclosure date, or remediation commitment. A production program would need its own published terms.
This page gives evaluators a safe, bounded way to disclose a suspected issue in the Devopsify demo. It is deliberately not indexed and is not a production security commitment.
Only test assets you own or have explicit permission to test, and keep testing to the minimum needed to demonstrate impact. Stop if you encounter another person's data, credentials, private infrastructure, or a path to a real third-party system.
Do not attach a working credential, malware, destructive payload, or full database export. If you accidentally expose a secret, stop testing, avoid further access, and describe the exposure without forwarding the secret.
The demo makes no promise of a reward, response time, coordinated disclosure date, or remediation commitment. A production program would need its own published terms.
Provider, repository, browser, and hosting vulnerabilities must be reported to the relevant owner when they are outside Devopsify demo code or control.
Devopsify's AI assistant is not an authorization boundary. Any real operation must remain subject to server-side authorization, policy, scoped capabilities, approval, and audit controls. Demo behavior should not be used as evidence of a production security certification or compliance claim.
For general support rather than a suspected vulnerability, use contact and support.