Contact

Reporting wrong data, requesting a vendor correction, and disclosing a security issue.

One address

[email protected] — for all four of the things below. There is no form, no ticket system and no autoresponder; a person reads it.

EVULNABLE is an independent project, operated from the United States. There is no guaranteed response time. Reports that name a specific page and say what you expected instead get answered fastest, because they can be acted on without a reply first.

A vulnerability record is wrong

Worth separating two cases, because they have different fixes:

  • The upstream record is wrong. If CVSS, the CVE description or the KEV listing itself is incorrect, the fix belongs at NVD, CISA or the vendor — this site republishes what they publish, and correcting it here would put EVULNABLE at odds with the source of record. Every entry links back to its source for exactly this. Tell us anyway if it matters and we will note the dispute.
  • EVULNABLE is wrong about it. A score that does not match the evidence shown beside it, a chip that contradicts the record, a deadline computed wrongly, a CVE in the wrong scope. That is ours. Send the CVE identifier and the page.

You are a vendor and something about you is wrong

The comparison pages carry two different kinds of statement, and both can be corrected — differently.

  • A published fact — a capability, a price, a certification, a supported platform. If it is out of date or misread, send what it should say and where you publish it. Facts get corrected on evidence, and the research date on the page moves when they do.
  • An EVULNABLE assessment — a ranking, a "best fit" judgment, a strategic conclusion. These are labeled as assessments because they are opinion, and opinion is not corrected on request. Tell us what we have weighed wrongly and we will consider it; being unhappy with a placement is not by itself a correction.

No vendor pays for placement here and none is given advance sight of a comparison. That is what makes the rankings worth reading, and it is why the second bullet reads the way it does.

A security issue in this site

Read the coordinated disclosure policy first — it sets out the scope, what we ask of you, and what we undertake in return. It is also published as plain text at /security-policy.txt, which is where /.well-known/security.txt points tooling that looks there.

In short: report it to the same address, include enough to reproduce it, and do not test against anyone else's uploads or domains. There is no bug bounty. There is an acknowledgement, credit if you want it, and no legal action over research done in good faith within that policy.

Something you uploaded

EVULNABLE does not retain your uploaded scan as a stored account record. An analysis lives in this server's memory and is released when it expires, when you clear it, or when the service restarts — there is no account to look up and no stored copy to retrieve or delete. Operational and security logs are handled separately, and Privacy and data handling sets out both, along with where the limits of these promises are.

If you believe an analysis of yours is reachable by someone who should not reach it, that is a security report rather than a data request, and the section above applies.