Vulnerability Disclosure Policy
Effective date: August 5, 2026
Intagri Technologies LLC operates Dainvo and welcomes specific, good-faith reports that help us protect Dainvo users. This policy explains what testing we authorize, what remains prohibited, how to report a potential vulnerability, and what you can expect after reporting.
This policy applies prospectively from its effective date. It does not create retroactive rights, rewards, or compensation for activity or reports submitted before that date.
1. Scope
This policy covers the following Dainvo-owned products and public services:
dainvo.com,www.dainvo.com,users.dainvo.com,ai.dainvo.com,mcp.dainvo.com,maps.dainvo.com,downloads.dainvo.com, anddocs.dainvo.com;- Dainvo-owned public APIs and account systems; and
- official, publicly released Dainvo desktop and mobile applications.
Third-party infrastructure and services are not in scope, including Stripe, Cloudflare, Supabase, Microsoft, Google, Apple, app stores, and other providers. A vulnerability caused by Dainvo code or configuration that involves one of those services may still be reported, but you must not test the provider's infrastructure or other customers.
2. Authorized research and safe harbor
We authorize only good-faith research that follows every requirement below:
- Use only accounts you own or are expressly authorized to use, and use only your own test data.
- Keep requests targeted, low volume, and no more extensive than necessary to confirm the issue.
- Avoid privacy violations, service disruption, data loss, degraded performance, and harm to any person.
- Stop testing once you have enough evidence to explain the potential vulnerability.
- For Dainvo applications, use only normal user-accessible interfaces and normal product behavior.
- Comply with applicable law and with this policy throughout the research and disclosure process.
If you conduct research in good faith and comply with this policy, Dainvo will treat that activity as authorized for purposes of our Terms and will not initiate or support legal action solely because of that compliant activity. If a third party initiates legal action, Dainvo may state that your research complied with this policy. This safe harbor does not bind third parties or law enforcement, authorize unlawful conduct, or permit violations of third-party terms.
If you are unsure whether an action is permitted, stop before taking that action and ask through the protected reporting form.
3. Prohibited activities
This policy does not authorize you to:
- access, view, copy, change, delete, or disclose another person's account or data;
- use stolen credentials, credential stuffing, password spraying, phishing, pretexting, or social engineering;
- perform denial-of-service, load, stress, high-volume, or mass automated scanning;
- introduce malware, establish persistence, escalate privileges, move laterally, or access a command shell;
- exfiltrate data or test backups, physical locations, employees, contractors, or support personnel;
- test payments with real or stolen cards, intentionally create charges, or use disputes or chargebacks as a test;
- reverse engineer, decompile, disassemble, extract source code, or bypass DRM, licensing, payment, entitlement, update, authentication, or access controls;
- copy, clone, redistribute, publish, or use Dainvo software, designs, or non-public material to build a competing product; or
- test third-party systems, accounts, applications, networks, or provider infrastructure.
4. Sensitive or private data
If you unexpectedly encounter personal information, credentials, tokens, private content, payment information, or any data that is not yours, stop immediately. Do not continue exploring, download additional data, retain unnecessary copies, or share the data with anyone else.
Report what happened using the minimum redacted evidence necessary. Do not submit passwords, recovery codes, OAuth tokens, private keys, payment-card numbers, complete customer records, or other live secrets. Delete any inadvertently retained data after reporting unless Dainvo gives you specific preservation instructions.
5. How to report
Use the protected support form and selectSecurity disclosure. Please include:
- the affected hostname, URL, component, API, or application version;
- a clear description of the issue, potential impact, and required conditions;
- minimal, non-destructive steps to reproduce the issue using your own account and data;
- the date, time, time zone, and any relevant Dainvo request ID;
- redacted request and response details or screenshots when useful; and
- whether you encountered or retained any data that was not yours.
Paste the relevant details directly into the form. Do not send executable files, scripts, archives, malware, or links that require Dainvo to run hosted proof-of-concept code. The form accepts optional image, audio, or video evidence subject to its existing file limits.
6. Reports we may close without investigation
Dainvo may close duplicate, incomplete, out-of-scope, non-reproducible, or non-actionable submissions. Examples that are usually non-actionable without a demonstrated security impact include:
- automated scanner output without reproducible evidence or impact;
- missing optional headers, TLS grades, software-version disclosure, or other hardening observations alone;
- self-XSS or clickjacking on a page with no sensitive action;
- rate-limit observations without a practical bypass or security impact; and
- SPF, DKIM, DMARC, or third-party findings not caused by Dainvo-controlled code or configuration.
7. What you can expect
Dainvo targets acknowledgment of a complete report within seven business days. This target is not a service level agreement and does not promise that Dainvo will validate, remediate, or publicly discuss a report within any particular period. Priority and response timing depend on severity, reproducibility, available resources, and other operational needs.
Dainvo may request more information, provide status updates when practical, or share report details privately with service providers, professional advisers, or authorities when reasonably necessary to investigate, remediate, protect users, or comply with law.
8. Coordinated disclosure
Do not publicly disclose vulnerability details before Dainvo has had a reasonable opportunity to investigate and you have coordinated publication timing with us. This policy sets no fixed remediation or public-disclosure deadline. Publication timing must be agreed case by case. Dainvo will coordinate in good faith and provide progress updates when practical.
Dainvo does not maintain a public acknowledgments program. Any thanks are private and do not create a promise of public credit or compensation.
9. Relationship to other policies
This policy controls only for security-research conduct it expressly authorizes. TheDainvo Terms & Conditions and Privacy Policy continue to apply in all other respects.
The English version of this policy is authoritative. Any translation is provided for convenience, and the English version controls if a translation conflicts with it.
Dainvo may update or end this policy. Changes apply prospectively from the effective date shown on the updated page and do not retroactively authorize earlier conduct.