velsa

Reporting a security vulnerability.

Palladium Innovations, LLC welcomes good-faith reports of security vulnerabilities in Velsa and its public web properties. This page explains how to report, what to expect, and the safe-harbor terms for your research.

Last updated: 17 July 2026

Machine-readable /.well-known/security.txt
Acknowledgement within 3 business days

Scope

This policy covers the Velsa application and the public sites operated by Palladium Innovations — velsa.io and its subdomains, including demo.velsa.io. Third-party services we rely on are out of scope; please report issues in those to their respective operators.

How to report

Email security@velsa.io. To help us triage quickly, please include:

Please do not include customer data in your report. If a proof of concept requires sensitive data, describe it rather than attaching it.

What to expect

We acknowledge reports within 3 business days and will keep you informed as we triage and remediate. We ask that you give us a reasonable opportunity to remediate before any public disclosure, and we're happy to coordinate timing with you.

Safe harbor

We will not pursue legal action for good-faith, in-scope security research that respects the following rules:

If you make a good-faith effort to comply with this policy during your research, we will consider it authorized, and we will work with you to understand and resolve the issue quickly.

Out of scope

The following are not in scope for this program:

Rewards

We do not operate a paid bug-bounty program at this time. We're grateful for responsible disclosure and will gladly credit researchers who wish to be acknowledged.