Contact

Email security@sonavera.ai with a clear description, affected URL or component, reproduction steps, and the impact you observed. Please omit real biometric data, customer data, credentials, and secrets.

Authorized research

Sonavera authorizes good-faith security research on the Sonavera Public Demo, including reverse engineering and attempts to bypass Demo controls. This authorization covers the Demo and Sonavera-owned endpoints used by sessions started there; customer, administrator, internal, and third-party systems are excluded.

Use only sessions, identifiers, accounts, and media you own or are authorized to use. Avoid disruption and test only enough to demonstrate an issue. Do not intentionally access anyone else’s data, perform load or denial-of-service testing, use social engineering or malware, or test third-party services. If you encounter data you are not authorized to access—including personal or biometric data, credentials, secrets, or customer data—stop and report it without copying or sharing it.

What to expect

Report vulnerabilities privately and coordinate disclosure while we investigate. Sonavera will not pursue legal action for good-faith research consistent with this policy. We will acknowledge a well-formed report and investigate it based on the issue’s risk. No bounty or payment is promised.