Security Practices

Security information and vulnerability reporting guidance for CVEalert.io

Poslední aktualizace: 11. června 2026

Security and responsible disclosure are important to us, and we welcome reports from researchers, users, and the wider security community.

TL;DR

Here’s a brief summary of our data security practices:

  • All data is encrypted in transit
  • All visitor data is hosted in the EU on EU-owned servers
  • User passwords are hashed and salted
  • You can enable two-factor authentication (2FA)
  • Regular vulnerability scans are conducted
  • Security-sensitive code and configuration changes are reviewed before release
  • We use automated checks to help detect insecure code patterns, leaked secrets, and risky CI/CD configuration
  • We keep dependencies, infrastructure, and application components up to date
  • We use dependency monitoring and automated update workflows where appropriate
  • We limit access to production systems and sensitive operational data
  • Data access is firewalled and user-restricted
  • All data is backed up on remote backups
  • Performance is monitored and uptime is disclosed
  • We monitor for security issues affecting our service and respond based on risk
  • We don’t store debit or credit card details
  • We do not sell your data and only share it with trusted service providers where necessary to operate and provide the service
  • We support responsible vulnerability disclosure

Reporting vulnerabilities

If you believe you have found a security vulnerability in the service, please report it to:

  • security@cvealert.io

Reports made in good faith help us improve security for everyone.

security.txt

We publish a security.txt file to make vulnerability reporting easier for security researchers and automated tools.

The file should be available at: