Report a security issue
If you believe you have found a security vulnerability in Everest or any Log10 service, please tell us.
Email security@log10.io
What to include
The affected URL, feature or API endpoint
Steps to reproduce, with any proof-of-concept code or screenshots
The impact you think it has
How we can reach you
In scope
app.everest.log10.io , api.everest.log10.io and sandbox.app.everest.log10.io
The published SDKs, @log10/everest-sdk and log10-everest-sdk
Out of scope
Services run by other companies, including AWS, Google and Microsoft sign-in, and model providers. Report those to the provider.
Denial-of-service and high-volume automated scanning
Social engineering of Log10 staff or customers, and physical attacks
Reports with no security impact, such as missing headers with no demonstrated exploit
What to expect
We acknowledge reports within 2 business days .
We tell you whether we can reproduce the issue and what we plan to do, within 5 business days of acknowledging.
We keep you informed until the issue is resolved, and we credit you if you would like.
Testing guidelines
Use only accounts and workspaces you own or have permission to test.
Stop and report as soon as you can see data belonging to someone else, and delete any copy you hold.
Avoid tests that degrade the service for others.
Give us reasonable time to fix an issue before you disclose it publicly.
Safe harbor
We will not pursue legal action against anyone who reports an issue in good faith and follows these guidelines.
Customers
Customers reporting a suspected incident involving their own data can also use the contacts named in their agreement.
The third parties that process customer data for Log10 are listed on the Subprocessors page.



