Home / Vulnerability disclosure
Vulnerability disclosure
If you have found a security problem in eVerbary, we want to hear about it, and we would rather hear it from you than from someone else. This page says how to reach us, what we will do, and how long it should take.
$24.95/page
Flat rate per page, up to 250 words. No hidden fees.
100% USCIS acceptance
Every certified translation is guaranteed to be accepted by USCIS.
24-hour delivery
Most 1-3 page documents are delivered within 24 hours. Same-day available.
How to report
Email support@everbary.com with “Security” in the subject line. It reaches a person, not a queue.
Useful things to include: what you found, the steps to reproduce it, what an attacker could do with it, and how you would like to be credited. Please do not post it publicly before we have had a chance to fix it.
What we commit to
- We acknowledge your report within 2 business days.
- We tell you whether we consider it a real issue, and at what severity, within 5 business days.
- We tell you when it is fixed, and we credit you if you want to be credited.
How quickly we fix things
Severity is judged by what an attacker could actually do, not by the category a scanner assigns.
- High — customer documents or accounts exposed, or the service taken down: work starts immediately and we aim to resolve within 3 business days, with a mitigation in place sooner where one exists.
- Medium — a real weakness that needs other conditions to be exploited: resolved within 10 business days.
- Low — hardening and defence in depth, with no realistic path to customer data: resolved within 30 days, or closed with a written reason.
- If a fix will take longer than the window, we tell you why and when instead of letting the date pass in silence.
Testing safely, and our promise to you
We will not pursue legal action against anyone who reports a problem in good faith under this policy, and we will not ask your employer to. That promise holds as long as you stay within the rules below.
- Use only accounts you own. Do not access, modify or download another customer's documents — if you find you can, stop there and tell us; demonstrating the door opens is enough.
- No denial of service, no load testing, no spam, no social engineering of our staff, customers or translators.
- Give us a reasonable chance to fix it before going public.
- Do not keep customer data you came across. Tell us what you saw and delete it.
Out of scope
Reports that need no action from us: missing headers with no demonstrated impact, software version numbers on their own, findings that only affect outdated browsers, and automated scanner output with no working proof. Issues in Stripe, PayPal, Google Cloud or another provider should go to that provider, though we are glad to be told.
Frequently asked questions
Where do I send a security report?
support@everbary.com with "Security" in the subject line. We acknowledge within 2 business days.
Do you pay for reports?
We do not run a paid bounty programme. We credit researchers who want the credit, and we answer quickly and honestly.
How fast do you fix things?
High severity within 3 business days, medium within 10 business days, low within 30 days. If something will take longer we tell you why and when.
Will you take legal action against me?
No, as long as you acted in good faith and followed the rules on this page: your own accounts only, no denial of service, no keeping customer data, and a reasonable chance to fix it first.
Can I test against your live site?
Yes, against accounts you own, without denial of service or load testing. eVerbary has no separate test environment.
Questions about any of this?
Write to support@everbary.com and a person will answer.