Security Submissions

How to Contact Us

Please report security vulnerabilities in our software products or on this website to security@devontechnologies.com. Helpful details: affected version or URL, steps to reproduce, and an assessment of the impact.

We acknowledge reports and fix confirmed vulnerabilities promptly. We welcome public disclosure by the reporter once a fix is available, or 90 days after the report at the latest (coordinated disclosure).

No Rewards, Sorry

There is no bug bounty program and we do not give rewards, payments, or credits for reports — including on request.

Out of Scope

  • SPF, DKIM, and DMARC configuration
  • Missing security headers without demonstrable impact (CSP, X-Frame-Options, etc.)
  • Clickjacking on pages without security-sensitive actions
  • Visible software versions, banners, directory listings without sensitive content
  • Automated scanner output without a verified proof of concept
  • Social engineering, phishing, physical access
  • Denial of service and volumetric attacks

We will not reply to reports on these topics.