TRUST
Responsible disclosure
Responsible disclosure
Responsible disclosure
Last updated: August 1, 2026
Last updated: August 1, 2026
Effective Date: March 15, 2026
Alvin Technologies, Ltd. (“Alvin,” “we,” “us” or “our”) takes the security of our systems and the information entrusted to us seriously. We welcome good-faith reports from security researchers and members of the public who believe they have identified a potential security vulnerability affecting an Alvin website, application or service.
This policy explains how to report a suspected vulnerability, what security research is permitted and what you can expect from Alvin after submitting a report.
1. How to report a vulnerability
Please send suspected security vulnerabilities to:
Use the subject line:
Security vulnerability report
Your report should include enough information for us to understand and reproduce the issue. Please identify the affected website, application, page, endpoint or feature, explain the nature and potential impact of the vulnerability and provide clear steps for reproducing it.
Where helpful, you may also include screenshots, logs, relevant request and response details, limited proof-of-concept code and any suggested remediation. Please remove or redact unnecessary personal information, credentials and confidential customer information before submitting your report.
Do not include exploit code or sensitive data beyond what is reasonably necessary to demonstrate the issue.
2. Systems covered by this policy
This policy applies to Alvin-owned and Alvin-operated public websites, portals, applications and services, including:
alvin.finance
portal.alvin.finance
Alvin Envoy
Alvin Travel
Alvin Protocol
It also applies to other internet-accessible systems where Alvin has expressly authorized security testing or directed researchers to this policy.
Third-party systems, suppliers, travel platforms, banks, payment providers, infrastructure providers, communications providers and other services that Alvin does not control are outside the scope of this policy, even where they are linked to or integrated with an Alvin service.
Where a vulnerability affecting a third-party provider could materially affect Alvin customers or services, you may notify us in addition to reporting the issue to the relevant provider.
3. Permitted security research
Alvin considers security research to be conducted in good faith where it is intended to identify and report a vulnerability, is limited to what is reasonably necessary to confirm the issue and is performed in a manner designed to avoid harm.
You should use accounts, systems and data that you own or are expressly authorized to use wherever possible. You should make reasonable efforts to protect user privacy, avoid accessing information that does not belong to you and stop testing once you have gathered enough evidence to demonstrate the vulnerability.
Automated testing must be limited in volume and configured so that it does not impair service availability, overwhelm systems, create excessive traffic or affect other users.
4. Prohibited activity
This policy does not authorize activity that could harm Alvin, our customers, users, partners, suppliers or other parties.
You must not intentionally access, download, alter, delete, retain, transmit or disclose personal information, customer information or confidential information that you are not authorized to access.
You must not conduct denial-of-service testing, distributed denial-of-service testing, load testing, stress testing or any other activity that could degrade, interrupt or impair an Alvin service.
You must not use social engineering, phishing, credential theft, physical intrusion, employee impersonation or attacks directed at Alvin personnel, customers, users, suppliers or partners.
You must not introduce malware, ransomware, destructive code, persistent access mechanisms or backdoors.
You must not alter production information, change user permissions, initiate payments, make bookings, send communications, contact travelers or suppliers or perform operational actions through an account or system you are not authorized to control.
You must not exploit a vulnerability beyond the minimum extent reasonably necessary to confirm its existence and explain its potential impact.
You must not publicly disclose a suspected vulnerability before Alvin has had a reasonable opportunity to investigate and address it.
5. Sensitive information encountered during research
If you encounter personal information, payment information, credentials, passport information, travel records, confidential customer information or other sensitive data, stop testing immediately.
Do not copy, download, retain, transmit, disclose or otherwise use the information except to the minimum extent necessary to notify Alvin that exposure occurred.
Your report should describe the type of information encountered without including the information itself unless Alvin specifically requests a limited sample through an agreed secure method.
Any sensitive information inadvertently retained during testing should be securely deleted after Alvin confirms receipt of the report, unless preservation is legally required.
6. Safe harbor
Alvin will not initiate legal action against a researcher for security research that Alvin reasonably determines was conducted in good faith and in accordance with this policy.
This safe harbor applies only where the researcher has acted to avoid harm, respected privacy, remained within the scope of this policy and promptly reported the vulnerability to Alvin.
Research conducted consistently with this policy will be considered authorized for the limited purpose of identifying and reporting a security vulnerability.
This policy does not provide authorization to violate applicable law, access third-party systems, interfere with other users or undertake activity prohibited by this policy. Alvin cannot authorize testing of infrastructure or services owned or controlled by third parties.
If you are uncertain whether a proposed activity is permitted, contact hello@alvin.finance before proceeding.
7. What you can expect from Alvin
After receiving a vulnerability report, Alvin will acknowledge receipt within two business days.
We may contact you for additional information, clarification or assistance reproducing the issue. We will evaluate the report based on factors including severity, exploitability, affected systems, potential impact and whether the issue is already known.
Where a report identifies a valid vulnerability, Alvin will seek to investigate and address it within a timeframe appropriate to the risk and complexity of the issue. Some vulnerabilities may require coordination with infrastructure providers, suppliers or other third parties and may therefore take longer to resolve.
We may provide progress updates where reasonably practical, but we cannot guarantee a specific remediation date or disclose confidential information about our systems, customers, providers or internal security processes.
8. Coordinated disclosure
Please allow Alvin a reasonable opportunity to investigate and remediate a reported vulnerability before making it public.
The appropriate disclosure period will depend on the nature, severity and complexity of the issue. As a general expectation, please do not publicly disclose the vulnerability for at least 90 days after submitting a complete report unless Alvin agrees to an earlier disclosure date or additional time is reasonably required.
Any public disclosure must avoid exposing customer information, credentials, confidential system details or information that could materially increase the risk of exploitation.
Alvin may request that disclosure be delayed where remediation depends on a third party, customers require time to take protective action or immediate disclosure would create a material security, privacy or safety risk.
9. Compensation and recognition
Alvin does not currently operate a paid bug-bounty program. Submitting a vulnerability report does not create an entitlement to payment, reimbursement, employment, compensation or any other reward.
At Alvin’s discretion and with the researcher’s permission, we may acknowledge researchers who submit meaningful vulnerabilities and follow responsible disclosure practices.
We may decline recognition where a report concerns an issue that is already known, cannot be reproduced, has no meaningful security impact, falls outside the scope of this policy or was identified through activity that violated this policy.
10. Issues that may not qualify
The following issues will generally not be treated as reportable vulnerabilities unless they create a demonstrable security impact:
automated scanner output without evidence of exploitability
missing security headers without a practical security consequence
self-cross-site scripting
user-interface concerns without a security impact
rate-limiting observations that do not enable meaningful abuse
outdated or unsupported browser behavior
vulnerabilities requiring physical access to an already unlocked device
hypothetical attacks without a credible attack path
information that was intentionally made public
issues affecting obsolete or unsupported software
email-spoofing reports without evidence of inadequate email-authentication controls
We still encourage you to report an issue where you reasonably believe the surrounding circumstances create a meaningful risk.
11. Privacy
Information submitted through this disclosure process will be used to evaluate, investigate, remediate and document the reported issue.
We may share relevant report information with Alvin personnel, contractors, professional advisers, infrastructure providers or other third parties where reasonably necessary to investigate or resolve the vulnerability.
We will handle personal information submitted through this process in accordance with Alvin’s Privacy Policy.
12. No waiver
This policy does not waive any rights or remedies available to Alvin, our customers, users, suppliers or other parties in relation to conduct that falls outside this policy, causes harm, violates applicable law or is not undertaken in good faith.
Alvin may update this policy from time to time. The version in effect when a report is submitted will generally govern that report.
13. Contact
Please report suspected security vulnerabilities to:
Use the subject line:
Security vulnerability report
Effective Date: March 15, 2026
Alvin Technologies, Ltd. (“Alvin,” “we,” “us” or “our”) takes the security of our systems and the information entrusted to us seriously. We welcome good-faith reports from security researchers and members of the public who believe they have identified a potential security vulnerability affecting an Alvin website, application or service.
This policy explains how to report a suspected vulnerability, what security research is permitted and what you can expect from Alvin after submitting a report.
1. How to report a vulnerability
Please send suspected security vulnerabilities to:
Use the subject line:
Security vulnerability report
Your report should include enough information for us to understand and reproduce the issue. Please identify the affected website, application, page, endpoint or feature, explain the nature and potential impact of the vulnerability and provide clear steps for reproducing it.
Where helpful, you may also include screenshots, logs, relevant request and response details, limited proof-of-concept code and any suggested remediation. Please remove or redact unnecessary personal information, credentials and confidential customer information before submitting your report.
Do not include exploit code or sensitive data beyond what is reasonably necessary to demonstrate the issue.
2. Systems covered by this policy
This policy applies to Alvin-owned and Alvin-operated public websites, portals, applications and services, including:
alvin.finance
portal.alvin.finance
Alvin Envoy
Alvin Travel
Alvin Protocol
It also applies to other internet-accessible systems where Alvin has expressly authorized security testing or directed researchers to this policy.
Third-party systems, suppliers, travel platforms, banks, payment providers, infrastructure providers, communications providers and other services that Alvin does not control are outside the scope of this policy, even where they are linked to or integrated with an Alvin service.
Where a vulnerability affecting a third-party provider could materially affect Alvin customers or services, you may notify us in addition to reporting the issue to the relevant provider.
3. Permitted security research
Alvin considers security research to be conducted in good faith where it is intended to identify and report a vulnerability, is limited to what is reasonably necessary to confirm the issue and is performed in a manner designed to avoid harm.
You should use accounts, systems and data that you own or are expressly authorized to use wherever possible. You should make reasonable efforts to protect user privacy, avoid accessing information that does not belong to you and stop testing once you have gathered enough evidence to demonstrate the vulnerability.
Automated testing must be limited in volume and configured so that it does not impair service availability, overwhelm systems, create excessive traffic or affect other users.
4. Prohibited activity
This policy does not authorize activity that could harm Alvin, our customers, users, partners, suppliers or other parties.
You must not intentionally access, download, alter, delete, retain, transmit or disclose personal information, customer information or confidential information that you are not authorized to access.
You must not conduct denial-of-service testing, distributed denial-of-service testing, load testing, stress testing or any other activity that could degrade, interrupt or impair an Alvin service.
You must not use social engineering, phishing, credential theft, physical intrusion, employee impersonation or attacks directed at Alvin personnel, customers, users, suppliers or partners.
You must not introduce malware, ransomware, destructive code, persistent access mechanisms or backdoors.
You must not alter production information, change user permissions, initiate payments, make bookings, send communications, contact travelers or suppliers or perform operational actions through an account or system you are not authorized to control.
You must not exploit a vulnerability beyond the minimum extent reasonably necessary to confirm its existence and explain its potential impact.
You must not publicly disclose a suspected vulnerability before Alvin has had a reasonable opportunity to investigate and address it.
5. Sensitive information encountered during research
If you encounter personal information, payment information, credentials, passport information, travel records, confidential customer information or other sensitive data, stop testing immediately.
Do not copy, download, retain, transmit, disclose or otherwise use the information except to the minimum extent necessary to notify Alvin that exposure occurred.
Your report should describe the type of information encountered without including the information itself unless Alvin specifically requests a limited sample through an agreed secure method.
Any sensitive information inadvertently retained during testing should be securely deleted after Alvin confirms receipt of the report, unless preservation is legally required.
6. Safe harbor
Alvin will not initiate legal action against a researcher for security research that Alvin reasonably determines was conducted in good faith and in accordance with this policy.
This safe harbor applies only where the researcher has acted to avoid harm, respected privacy, remained within the scope of this policy and promptly reported the vulnerability to Alvin.
Research conducted consistently with this policy will be considered authorized for the limited purpose of identifying and reporting a security vulnerability.
This policy does not provide authorization to violate applicable law, access third-party systems, interfere with other users or undertake activity prohibited by this policy. Alvin cannot authorize testing of infrastructure or services owned or controlled by third parties.
If you are uncertain whether a proposed activity is permitted, contact hello@alvin.finance before proceeding.
7. What you can expect from Alvin
After receiving a vulnerability report, Alvin will acknowledge receipt within two business days.
We may contact you for additional information, clarification or assistance reproducing the issue. We will evaluate the report based on factors including severity, exploitability, affected systems, potential impact and whether the issue is already known.
Where a report identifies a valid vulnerability, Alvin will seek to investigate and address it within a timeframe appropriate to the risk and complexity of the issue. Some vulnerabilities may require coordination with infrastructure providers, suppliers or other third parties and may therefore take longer to resolve.
We may provide progress updates where reasonably practical, but we cannot guarantee a specific remediation date or disclose confidential information about our systems, customers, providers or internal security processes.
8. Coordinated disclosure
Please allow Alvin a reasonable opportunity to investigate and remediate a reported vulnerability before making it public.
The appropriate disclosure period will depend on the nature, severity and complexity of the issue. As a general expectation, please do not publicly disclose the vulnerability for at least 90 days after submitting a complete report unless Alvin agrees to an earlier disclosure date or additional time is reasonably required.
Any public disclosure must avoid exposing customer information, credentials, confidential system details or information that could materially increase the risk of exploitation.
Alvin may request that disclosure be delayed where remediation depends on a third party, customers require time to take protective action or immediate disclosure would create a material security, privacy or safety risk.
9. Compensation and recognition
Alvin does not currently operate a paid bug-bounty program. Submitting a vulnerability report does not create an entitlement to payment, reimbursement, employment, compensation or any other reward.
At Alvin’s discretion and with the researcher’s permission, we may acknowledge researchers who submit meaningful vulnerabilities and follow responsible disclosure practices.
We may decline recognition where a report concerns an issue that is already known, cannot be reproduced, has no meaningful security impact, falls outside the scope of this policy or was identified through activity that violated this policy.
10. Issues that may not qualify
The following issues will generally not be treated as reportable vulnerabilities unless they create a demonstrable security impact:
automated scanner output without evidence of exploitability
missing security headers without a practical security consequence
self-cross-site scripting
user-interface concerns without a security impact
rate-limiting observations that do not enable meaningful abuse
outdated or unsupported browser behavior
vulnerabilities requiring physical access to an already unlocked device
hypothetical attacks without a credible attack path
information that was intentionally made public
issues affecting obsolete or unsupported software
email-spoofing reports without evidence of inadequate email-authentication controls
We still encourage you to report an issue where you reasonably believe the surrounding circumstances create a meaningful risk.
11. Privacy
Information submitted through this disclosure process will be used to evaluate, investigate, remediate and document the reported issue.
We may share relevant report information with Alvin personnel, contractors, professional advisers, infrastructure providers or other third parties where reasonably necessary to investigate or resolve the vulnerability.
We will handle personal information submitted through this process in accordance with Alvin’s Privacy Policy.
12. No waiver
This policy does not waive any rights or remedies available to Alvin, our customers, users, suppliers or other parties in relation to conduct that falls outside this policy, causes harm, violates applicable law or is not undertaken in good faith.
Alvin may update this policy from time to time. The version in effect when a report is submitted will generally govern that report.
13. Contact
Please report suspected security vulnerabilities to:
Use the subject line:
Security vulnerability report