Responsible disclosure

Report platform findings privately.

Use the arena for in-scope Phalanx attacks. Report vulnerabilities in the arena platform, evidence system, or private-data boundary directly to Invarra instead of testing them publicly.

Effective August 8, 2026

Security contact

Email [email protected] with the subject “Phalanx security disclosure.” Include a concise impact description, affected route or component, safe reproduction steps, and a way to contact you. Use identifiers and hashes instead of harmful payload text whenever possible.

Good-faith handling

Invarra will treat research as good faith when it stays within the published authorization, avoids privacy violations and service disruption, reports platform vulnerabilities privately, and gives Invarra reasonable time to investigate before disclosure.

This is not permission to access data belonging to others, bypass accounts, extract secrets, degrade service, create real side effects, or test third-party systems.

What to expect

  • Acknowledgement as soon as practical, with priority based on impact and reproducibility.
  • A request for additional safe evidence when needed.
  • Status updates for confirmed high-impact findings when contact information is available.
  • No promise of payment or public acknowledgement unless agreed separately in writing.

Public key and canonical policy

The canonical machine-readable security contact is published at /.well-known/security.txt. Current arena scope and authorization are defined by the Terms and Arena Rules linked below.