Valence
FAQ Disclaimer Terms Privacy Security
Legal

Security & Vulnerability Disclosure

Last updated: June 2026

We take the security of Valence and your financial data seriously. This page explains how to report a vulnerability and what to expect in return. A machine-readable version of these contact details is published at /.well-known/security.txt (RFC 9116).

1 · Reporting a vulnerability

Please email [email protected] with:

  • A description of the issue and the impact you believe it has.
  • Step-by-step instructions to reproduce it (proof-of-concept, affected URL or endpoint, request and response if relevant).
  • Any preconditions (account tier, configuration) needed to trigger it.

Please do not open a public issue for security reports, and allow us a reasonable window to investigate and remediate before any public disclosure.

2 · What to expect

  • We aim to acknowledge a report within 5 business days.
  • We will keep you informed of our progress while we validate and fix the issue.
  • With your permission, we are happy to credit you once a fix has shipped.

3 · Scope

In scope:

  • The web application and its API (authentication, session handling, portfolio and transaction data, billing flows).
  • Per-user data isolation, access control, and any path that could expose another user's data.
  • Server-side input handling (uploads, imports, query parameters).

Out of scope:

  • Denial-of-service and volumetric attacks.
  • Findings that require a compromised device, a malicious browser extension, or physical access.
  • Reports from automated scanners with no demonstrated, exploitable impact.
  • Best-practice suggestions without a concrete security impact.
  • Social engineering of our staff or users.

4 · Safe harbour

We will not pursue or support legal action against researchers who:

  • Act in good faith and follow this policy.
  • Avoid privacy violations, data destruction, and service degradation.
  • Only interact with accounts they own or have explicit permission to test.
  • Give us a reasonable time to remediate before public disclosure.

5 · Contact

Security reports and questions: [email protected].

Valence · Portfolio Tracker · FAQ · Terms of Service · Privacy Policy · Disclaimer · Security · Contact · Report a bug