Legal
Security & Vulnerability Disclosure
Last updated: June 2026
We take the security of Valence and your financial data seriously. This page explains how to report a vulnerability and what to expect in return. A machine-readable version of these contact details is published at /.well-known/security.txt (RFC 9116).
1 · Reporting a vulnerability
Please email [email protected] with:
- A description of the issue and the impact you believe it has.
- Step-by-step instructions to reproduce it (proof-of-concept, affected URL or endpoint, request and response if relevant).
- Any preconditions (account tier, configuration) needed to trigger it.
Please do not open a public issue for security reports, and allow us a reasonable window to investigate and remediate before any public disclosure.
2 · What to expect
- We aim to acknowledge a report within 5 business days.
- We will keep you informed of our progress while we validate and fix the issue.
- With your permission, we are happy to credit you once a fix has shipped.
3 · Scope
In scope:
- The web application and its API (authentication, session handling, portfolio and transaction data, billing flows).
- Per-user data isolation, access control, and any path that could expose another user's data.
- Server-side input handling (uploads, imports, query parameters).
Out of scope:
- Denial-of-service and volumetric attacks.
- Findings that require a compromised device, a malicious browser extension, or physical access.
- Reports from automated scanners with no demonstrated, exploitable impact.
- Best-practice suggestions without a concrete security impact.
- Social engineering of our staff or users.
4 · Safe harbour
We will not pursue or support legal action against researchers who:
- Act in good faith and follow this policy.
- Avoid privacy violations, data destruction, and service degradation.
- Only interact with accounts they own or have explicit permission to test.
- Give us a reasonable time to remediate before public disclosure.
5 · Contact
Security reports and questions: [email protected].