1. Systems covered
This policy covers the public website at evitracore.com and any EviTraCore Heat Input release made publicly available by EviTraCore.
It does not cover Apple, Google, app-store infrastructure, hosting-provider systems, third-party websites or libraries, customer-managed devices or networks, or any domain or service not controlled by EviTraCore. Report a third-party issue directly to its owner unless the issue is caused by EviTraCore’s specific implementation.
2. Reporting procedure
Email hello@evitracore.com with:
- the affected URL, product, app version, operating system, and device where relevant;
- a concise description of the issue and its likely impact;
- the minimum steps needed to reproduce it; and
- redacted screenshots, logs, or proof-of-concept material that does not expose personal data, credentials, or confidential customer information.
Do not send live passwords, access tokens, private keys, or unnecessary personal data. If sensitive material is essential, first ask by email how it should be transferred.
3. Conditions and limitations for testing
This page does not grant permission to access accounts, data, devices, or systems that are not yours. Active security testing beyond normal product use requires prior written authorisation from the system owner.
- Use only accounts, records, and devices you own or are expressly authorised to test.
- Use the smallest number of requests and the minimum access needed to confirm the issue.
- Stop immediately if you encounter another person’s data, credentials, or a risk to availability or safety.
- Do not retain, copy, alter, delete, or disclose data encountered unintentionally.
4. Prohibited activity
Do not perform denial-of-service or load testing, destructive testing, malware deployment, persistence, credential attacks, social engineering, phishing, spam, physical intrusion, supply-chain attacks, or testing of third-party services. Do not disrupt users, transactions, production work, or app-store operation.
5. Assessment and remediation
We will review reports sent to the security address, confirm whether the reported system is controlled by EviTraCore, and assess reproducibility and impact. We may request additional information, coordinate a correction, or direct a third-party issue to the relevant owner. Receipt of an email does not by itself confirm a vulnerability or create a service-level commitment.
Please allow reasonable time for investigation and correction before public disclosure. We will coordinate disclosure when practical, but may need to limit details that could expose users, confidential information, or an unresolved risk.
6. Support enquiries and follow-up
Security reports are handled through hello@evitracore.com. We may contact the reporter for clarification and, where practical, confirm when the reported issue has been addressed.
For questions about Heat Input features, installation, purchases, or normal operation, use hello@evitracore.com. A security report does not create a commercial support agreement or guaranteed response time.