Embernel/Security
Security
If you have found a vulnerability in any Embernel product, we want to hear about it. This page explains how to report it and what to expect in return.
Last updated 1 September 2026 · Covers all Embernel products
Draft — needs your review This page is a working template written to match how the group is described elsewhere on the site. Check every statement against what you actually do before publishing, and have a lawyer review the final wording. Placeholders are marked in square brackets.
Send details to security@embernel.com. Include the affected URL or endpoint, the steps to reproduce, and what an attacker could achieve. If you would like to encrypt your report, our PGP key is at [key URL].
Reports that consist only of automated scanner output, missing best-practice headers with no demonstrated impact, or issues in third-party services we do not control.
[Describe only what you actually do today: encryption in transit and at rest, access control and least privilege, backup and restore testing, dependency scanning, logging and alerting, and incident response. Remove anything you have not implemented.]
[List only certifications you hold and can evidence, with the issuing body and date. If an audit is in progress, say that instead of implying it is complete. Do not claim SOC 2, ISO 27001 or similar until the report is in hand.]
Get in touch
Write to security@embernel.com. We answer every report, including the ones that turn out to be nothing.