VULNERABILITY DISCLOSURE REPORT
Okeenea Digital, the company behind Evelity, welcomes vulnerability reports from security researchers and any person acting in good faith. This policy explains how to report a vulnerability to us and the rules of coordinated disclosure.
1. How to report a vulnerability
Send your report to security@evelity.com, preferably in French or English, including: a description of the vulnerability and its impact, the steps to reproduce it (URL, requests, test accounts), a proof of concept (screenshots, logs) and your contact details. Please do not publicly disclose the vulnerability before we have fixed it and mutually agreed to do so.
2. Our commitments
- Acknowledgement of your report within 5 business days.
- Regular updates on the progress of the remediation.
- Remediation of confirmed vulnerabilities within timeframes proportionate to their severity.
- Safe harbor: we will not take legal action against anyone acting in good faith and in strict compliance with this policy.
3. Scope
In scope: the evelity.com website, the Evelity back office, the Evelity mobile application and the associated APIs.
Out of scope: denial-of-service (DoS) attacks, destructive tests or tests altering data integrity, social engineering, physical access, services operated by third parties/sub-processors, and already-known vulnerabilities with no demonstrated impact on Evelity.
4. Rules of conduct
- Act in good faith, without malicious intent or unfair commercial purpose.
- Do not access, modify, delete or exfiltrate data that does not belong to you; if you accidentally access personal data, stop immediately and inform us.
- Do not degrade or disrupt our services.
- Keep the vulnerability confidential until disclosure has been coordinated.
5. Coordinated disclosure
We ask you to allow a 90-day period between your report and any public disclosure, so that we can fix the issue and protect our users. This period may be adjusted by mutual agreement depending on the complexity of the fix.
6. Rewards
Evelity does not offer a bug bounty programme. With your consent, we may nonetheless publicly thank you for your contribution.
7. Personal data and legal framework
If a report reveals a personal data breach, we apply our incident management procedure and notify the CNIL within the legal 72-hour deadline, together with our DPO. Research conducted in compliance with this policy is deemed authorised; outside this framework, French law (Articles 323-1 et seq. of the Criminal Code) remains applicable. Article L.2321-4 of the French Defence Code also allows a vulnerability to be reported in good faith to the ANSSI (the French cybersecurity agency).
8. Contact
Reporting: security@evelity.com — Discoverability: /.well-known/security.txt (RFC 9116) — Data protection: dpo-digital@okeenea.com.
Version 1.0 — Last updated: 17 July 2026.