Vulnerability Disclosure Policy

Last updated: 12 February 2026

1. Introduction

Varangian Group Ltd welcomes reports of security vulnerabilities in our websites, services, and infrastructure. We are committed to working with security researchers to verify and address potential vulnerabilities.

This policy describes how to report vulnerabilities, what to expect from us, and what we ask of you.


2. Scope

In Scope

Out of Scope


3. How to Report

Send your report to: security@varangian.ai

If you wish to encrypt your report, our PGP key is available at: [varangian.ai/.well-known/security.txt]

What to Include


4. What We Ask of You


5. What We Commit To


6. Safe Harbour

We consider security research conducted in accordance with this policy to be:

If legal action is initiated by a third party against you for activities conducted in accordance with this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.

This safe harbour does not extend to activities that:


7. Disclosure

We follow coordinated disclosure principles:


8. Recognition

We do not currently operate a paid bug bounty programme. However, we value the contributions of the security research community and, with your consent, we will:


9. Contact


10. References

This policy is aligned with: