Report a security issue

If you believe you have found a security vulnerability in Everest or any Log10 service, please tell us.

What to include

  • The affected URL, feature or API endpoint

  • Steps to reproduce, with any proof-of-concept code or screenshots

  • The impact you think it has

  • How we can reach you

In scope

  • app.everest.log10.io , api.everest.log10.io and sandbox.app.everest.log10.io

  • The published SDKs, @log10/everest-sdk and log10-everest-sdk

Out of scope

  • Services run by other companies, including AWS, Google and Microsoft sign-in, and model providers. Report those to the provider.

  • Denial-of-service and high-volume automated scanning

  • Social engineering of Log10 staff or customers, and physical attacks

  • Reports with no security impact, such as missing headers with no demonstrated exploit

What to expect

  • We acknowledge reports within 2 business days .

  • We tell you whether we can reproduce the issue and what we plan to do, within 5 business days of acknowledging.

  • We keep you informed until the issue is resolved, and we credit you if you would like.

Testing guidelines

  • Use only accounts and workspaces you own or have permission to test.

  • Stop and report as soon as you can see data belonging to someone else, and delete any copy you hold.

  • Avoid tests that degrade the service for others.

  • Give us reasonable time to fix an issue before you disclose it publicly.

Safe harbor

We will not pursue legal action against anyone who reports an issue in good faith and follows these guidelines.

Customers

Customers reporting a suspected incident involving their own data can also use the contacts named in their agreement.

The third parties that process customer data for Log10 are listed on the Subprocessors page.

© Copyright 2026 Log10, Inc. All rights reserved.

© Copyright 2025 Log10, Inc. All rights reserved.

© Copyright 2025 Log10, Inc. All rights reserved.