Responsible Disclosure & Vulnerability Reporting

Vela Cloud Ltd, operating as Vela

Last updated: July 27, 2026

Our Commitment to Security Research

Vela Cloud Ltd welcomes responsible security research and values the contribution of the security community. We are committed to working with security researchers to identify, report, and remediate security vulnerabilities quickly, fairly, and confidentially.

This policy establishes clear guidelines for reporting vulnerabilities, protections for researchers acting in good faith, and consequences for unauthorized testing.

Authorized Testing

Security testing is only permitted under the following conditions:

  • You have obtained prior written authorization from Vela Cloud Ltd
  • You have signed a Responsible Disclosure Agreement that explicitly authorizes the testing
  • Your testing is strictly limited to the scope defined in the agreement
  • You do not access, extract, modify, or retain any data belonging to other users or customers

To request authorization for security testing, email [email protected] with your name, organization, testing scope, and dates. We will review and respond within 5 business days.

Prohibited Activities

The following are not permitted and violate these Terms:

  • Conducting "unsolicited" or "unauthorized" security testing
  • Testing production accounts or infrastructure without written authorization
  • Extracting, exfiltrating, or retaining customer data
  • Disclosing findings publicly before coordinated resolution
  • Testing during high-traffic periods or in ways that degrade service
  • Attempting to exploit vulnerabilities for personal gain

Consequences of Unauthorized Testing

Unauthorized or "unsolicited" security testing violates Vela's Terms of Use (Section 3a). Depending on the jurisdiction and nature of the activity — including the method of access, whether data was exfiltrated, and the intent — such testing may also trigger civil or criminal liability under applicable law. In the United States, this includes the Computer Fraud and Abuse Act (which requires unauthorized access with intent to defraud or reckless disregard for causing damage exceeding $5,000). In Israel, relevant provisions are found in Israel's Computer Law, 5755-1995. Vela reserves all rights to pursue civil and criminal remedies under applicable law.

Upon discovery of unauthorized testing, Vela Cloud Ltd will:

  • Immediately terminate all account(s) used in testing (irreversible)
  • Revoke all access to the platform
  • Forfeit all subscription fees and credits — no refunds will be issued
  • Reserve the right to pursue legal remedies under applicable law, including civil and criminal action
  • Not issue letters of recommendation, certificates, or public acknowledgments
  • Not participate in CVE allocation or public vulnerability disclosure

Account termination is immediate, final, and cannot be appealed.

Responsible Reporting Process

If you have identified a potential security vulnerability in Vela Cloud Ltd, please follow this process:

Step 1: Contact Us Securely

Email [email protected] with:

  • Your name, organization, and contact details
  • Description of the potential vulnerability
  • Affected component (e.g., authentication, API endpoint, UI)
  • Proof of concept (if applicable)
  • Suggested fix or mitigation (if you have one)

Step 2: Do Not Disclose Publicly

We will acknowledge receipt within 24 hours. During our investigation:

  • Do not disclose the issue to any third party
  • Do not publish findings on social media, blogs, or vulnerability databases
  • Do not test the vulnerability further beyond your initial discovery
  • Do not attempt exploitation or data extraction

Step 3: Coordinated Resolution

We will:

  • Investigate and confirm the vulnerability (typically 3–5 business days)
  • Develop and deploy a fix
  • Verify the fix resolves the issue
  • Notify you when the issue is resolved
  • Offer recognition on our Security Thank You page (if you wish)

Step 4: Coordinated Disclosure Timeline

After patch deployment:

  • Critical vulnerabilities: Public disclosure 30 days after patch
  • High severity: Public disclosure 60 days after patch
  • Medium/Low severity: Public disclosure 90 days after patch

Security Researcher Safe Harbor

Vela Cloud Ltd recognizes the value of security research conducted in accordance with this policy. As a matter of company policy, and consistent with responsible disclosure best practices, we provide the following safe harbor for researchers acting in good faith and within the scope of a signed Responsible Disclosure Agreement:

  • Good faith testing conducted under a signed Responsible Disclosure Agreement and within the authorized scope is not a violation of Vela's Terms of Use
  • We will not pursue legal or criminal action against researchers who:
    • Report vulnerabilities responsibly and promptly (within the agreed timeline)
    • Do not access, modify, or retain customer data beyond what is necessary to prove the vulnerability
    • Do not disclose findings publicly before coordinated resolution (per our timeline in Step 4)
    • Cooperate with our investigation and respect the scope limits in the Responsible Disclosure Agreement
  • We will not report good faith researchers to law enforcement for security testing conducted within the authorized scope
  • Note: This safe harbor reflects Vela's commitment to responsible disclosure. It does not alter, limit, or supersede any obligation under applicable data protection law (including GDPR, Israeli Privacy Protection Law, or US law). Researchers should be aware that jurisdiction-specific laws may impose additional obligations.

Data Breach Notification

If a vulnerability results in unauthorized access to customer data, Vela will notify affected customers and regulatory authorities in accordance with applicable law:

  • Within 72 hours: Notification to affected data subjects (per GDPR Article 33)
  • Included in notification: Type of data accessed, date range, and recommended protective actions
  • Regulatory notification: Notification to applicable data protection authorities and supervisory bodies
  • Documentation: All incidents maintained in our compliance records (available to enterprise customers and regulators on request)

Terms & Governing Law

This Responsible Disclosure Policy is incorporated into our Terms of Use by reference. Any disputes arising from this policy are governed by the laws of the State of Israel, and parties submit to the exclusive jurisdiction of the Tel Aviv courts.

For information about data processing in connection with vulnerability reports, see our Privacy Policy.

Questions?

For questions about this policy or to report a vulnerability, contact:

Vela Cloud Ltd, Security Team
Email: [email protected]
Address: 28 HaArba'a St, Tel Aviv 6473925, Israel