Security Practices
Security information and vulnerability reporting guidance for CVEalert.io
Poslední aktualizace: 11. června 2026
Security and responsible disclosure are important to us, and we welcome reports from researchers, users, and the wider security community.
TL;DR
Here’s a brief summary of our data security practices:
- All data is encrypted in transit
- All visitor data is hosted in the EU on EU-owned servers
- User passwords are hashed and salted
- You can enable two-factor authentication (2FA)
- Regular vulnerability scans are conducted
- Security-sensitive code and configuration changes are reviewed before release
- We use automated checks to help detect insecure code patterns, leaked secrets, and risky CI/CD configuration
- We keep dependencies, infrastructure, and application components up to date
- We use dependency monitoring and automated update workflows where appropriate
- We limit access to production systems and sensitive operational data
- Data access is firewalled and user-restricted
- All data is backed up on remote backups
- Performance is monitored and uptime is disclosed
- We monitor for security issues affecting our service and respond based on risk
- We don’t store debit or credit card details
- We do not sell your data and only share it with trusted service providers where necessary to operate and provide the service
- We support responsible vulnerability disclosure
Reporting vulnerabilities
If you believe you have found a security vulnerability in the service, please report it to:
security@cvealert.io
Reports made in good faith help us improve security for everyone.
security.txt
We publish a security.txt file to make vulnerability reporting easier for security researchers and automated tools.
The file should be available at: