Security Policy

Reporting a
security issue.

CIVITERA welcomes responsible disclosure of vulnerabilities affecting this website or our published materials.

Last updated 20 July 2026  ·  CIVITERA GovTech Inc.  ·  Delaware, USA

Reporting a vulnerability

If you believe you have found a security vulnerability in civitera.ai, please report it to security@civitera.ai. Include the affected URL, a description of the issue, and the steps required to reproduce it. Our machine-readable security contact is published at /security.txt and at the RFC 9116 canonical location /.well-known/security.txt.

What we ask

  • Give us a reasonable opportunity to remediate before any public disclosure.
  • Avoid privacy violations, service degradation, and destruction or modification of data.
  • Do not run automated scanning that materially degrades availability for others.
  • Do not attempt social engineering, physical intrusion, or access to systems beyond the scope of this website.

What we commit to

  • Acknowledge your report, normally within five business days.
  • Keep you informed as we investigate and remediate.
  • Not pursue legal action against researchers acting in good faith within this policy.

Scope

In scope: the civitera.ai website and its published assets. Out of scope: third-party services we do not control, and any matter relating to patent prosecution, which is handled through the United States Patent and Trademark Office rather than this channel.

Site security measures

This site is served over HTTPS with HSTS, a Content Security Policy restricting script sources, and standard protections including frame-ancestor restrictions, MIME-type sniffing prevention, and a restrictive referrer policy.

Please do not include confidential or export-controlled technical information in a vulnerability report. Report the security issue only.