Monaveo is built to ISO 27001, NIS2 and GDPR-aligned standards, with EU data-residency and a security-first engineering process. We welcome reports from security researchers and treat every good-faith report as a priority. This page is our Vulnerability Disclosure Programme (VDP).
Report to: security@monaveo.com
Machine-readable policy: /.well-known/security.txt (RFC 9116)
Operator: Monaveo Ltd. · Company No. 17173409 · England & Wales
In scope:
Out of scope: denial-of-service (DoS/DDoS) and volumetric testing; physical attacks; social engineering of staff or customers; spam or content-injection with no security impact; findings that require a rooted/jailbroken device or a compromised endpoint the researcher already controls; automated scanner output without a demonstrated, exploitable impact; and third-party services we do not operate (e.g. Stripe, Cloudflare, the underlying RustDesk transport).
If you make a good-faith effort to comply with this policy during your research, we will consider your research to be authorised, we will not pursue or support legal action against you, and we will work with you to understand and resolve the issue quickly. If legal action is initiated by a third party against you for activity that complied with this policy, we will make it known that your actions were authorised.
| Stage | Target |
|---|---|
| Acknowledge your report | within 3 business days |
| Initial triage & severity assessment | within 10 business days |
| Status updates while we remediate | at least every 10 business days |
| Remediation target (Critical / High) | 30 / 60 days where technically feasible |
Monaveo does not currently operate a paid bug-bounty. With your permission, we are glad to credit valid reporters in a public acknowledgements list. We treat every valid report as a genuine contribution to protecting our customers and their clients.
If your testing incidentally exposes personal data, stop, do not store or share it, and tell us in your report so we can meet our GDPR obligations. See our Privacy Policy, GDPR page and DPA.