devopsify
PlatformCapabilitiesSecurityFAQContactDocs
Sign inStart free
SECURITY / DISCLOSURE

Report a weakness without creating another one.

This page gives evaluators a safe, bounded way to disclose a suspected issue in the Devopsify demo. It is deliberately not indexed and is not a production security commitment.

Public demo documentationLast reviewed 05 August 2026

Responsible disclosure boundaries

Only test assets you own or have explicit permission to test, and keep testing to the minimum needed to demonstrate impact. Stop if you encounter another person's data, credentials, private infrastructure, or a path to a real third-party system.

  • Do not perform denial-of-service, stress testing, destructive actions, persistence, phishing, social engineering, or physical testing.
  • Do not access, modify, exfiltrate, retain, or share data that is not yours.
  • Do not scan cloud providers, repositories, domains, or infrastructure outside the demo scope.
  • Do not use a suspected issue to bypass tenant boundaries, approval controls, policy checks, or authentication beyond the minimal proof.

What to include in a report

  1. A concise description and affected public URL or workflow.
  2. Reproduction steps using mock data, including prerequisites and UTC timestamps.
  3. Impact assessment and a minimal proof of concept. Redact tokens, cookies, personal data, and infrastructure details.
  4. Your preferred reply channel and whether the issue is being disclosed elsewhere.

Do not attach a working credential, malware, destructive payload, or full database export. If you accidentally expose a secret, stop testing, avoid further access, and describe the exposure without forwarding the secret.

No bounty or SLA

The demo makes no promise of a reward, response time, coordinated disclosure date, or remediation commitment. A production program would need its own published terms.

Third-party scope

Provider, repository, browser, and hosting vulnerabilities must be reported to the relevant owner when they are outside Devopsify demo code or control.

Security posture and product boundaries

Devopsify's AI assistant is not an authorization boundary. Any real operation must remain subject to server-side authorization, policy, scoped capabilities, approval, and audit controls. Demo behavior should not be used as evidence of a production security certification or compliance claim.

For general support rather than a suspected vulnerability, use contact and support.

2024-2026 All Rights Reserved Devopsify.Net
ContactPrivacyGDPRCookiesTermsSecurityPlatform admin