monaveo ← Back to Home

Security & Vulnerability Disclosure

Last updated: July 17, 2026

Our commitment

Monaveo is built to ISO 27001, NIS2 and GDPR-aligned standards, with EU data-residency and a security-first engineering process. We welcome reports from security researchers and treat every good-faith report as a priority. This page is our Vulnerability Disclosure Programme (VDP).

Report to: security@monaveo.com

Machine-readable policy: /.well-known/security.txt (RFC 9116)

Operator: Monaveo Ltd. · Company No. 17173409 · England & Wales

1. Scope

In scope:

  • The Monaveo platform and its regional dashboards — app.monaveo.com (EU), us-app.monaveo.com (US)
  • The public website and portals — www.monaveo.com, connect.monaveo.com, help.monaveo.com, customer portals
  • The Monaveo endpoint agent, the Monaveo Connect desktop helper, and the Monaveo Connect mobile apps
  • The distribution host dl.monaveo.com and the backend API

Out of scope: denial-of-service (DoS/DDoS) and volumetric testing; physical attacks; social engineering of staff or customers; spam or content-injection with no security impact; findings that require a rooted/jailbroken device or a compromised endpoint the researcher already controls; automated scanner output without a demonstrated, exploitable impact; and third-party services we do not operate (e.g. Stripe, Cloudflare, the underlying RustDesk transport).

2. Safe harbour

If you make a good-faith effort to comply with this policy during your research, we will consider your research to be authorised, we will not pursue or support legal action against you, and we will work with you to understand and resolve the issue quickly. If legal action is initiated by a third party against you for activity that complied with this policy, we will make it known that your actions were authorised.

3. How to report

  • Email security@monaveo.com with a clear description, the affected asset/URL, reproduction steps, and any proof-of-concept.
  • Use a minimal proof-of-concept. Do not access, modify, or exfiltrate data that is not your own — stop as soon as impact is demonstrated.
  • Give us a reasonable time to remediate before any public disclosure (coordinated disclosure).

4. Our response commitment (SLA/SLO)

StageTarget
Acknowledge your reportwithin 3 business days
Initial triage & severity assessmentwithin 10 business days
Status updates while we remediateat least every 10 business days
Remediation target (Critical / High)30 / 60 days where technically feasible

5. Recognition

Monaveo does not currently operate a paid bug-bounty. With your permission, we are glad to credit valid reporters in a public acknowledgements list. We treat every valid report as a genuine contribution to protecting our customers and their clients.

6. Data protection

If your testing incidentally exposes personal data, stop, do not store or share it, and tell us in your report so we can meet our GDPR obligations. See our Privacy Policy, GDPR page and DPA.

© 2026 Monaveo by Monaveo Ltd. All rights reserved.

Monaveo Ltd. · Company No. 17173409 · Registered in England & Wales

Privacy Terms DPA GDPR Security Contact