Security and responsible disclosure
Report a security issue directly to Invarra.
Use the supported contact route for vulnerabilities affecting Phalanx, Phalanx vs the World, or invarra.ai. Do not include harmful payloads, credentials, private customer data, or raw exploit material in the first message.
Supported route
Enough to classify and route the report safely.
Choose Security disclosure in the contact form. The backend validates that classification and routes it to the private security intake. Start with a concise description, affected surface, reproducibility level, and a safe contact address. We will arrange a protected transfer method if more detail is needed.
Include
- Affected product or URL
- Impact at a high level
- Whether it is repeatable
- Safe contact information
Do not include initially
- Credentials or API keys
- Customer or personal data
- Raw harmful payloads
- Destructive proof of concept
Product security posture
Fail closed at the declared control boundary.
Missing release identity, invalid authenticated state, invalid permits, unavailable protected sinks, or an unavailable Wall do not produce an unprotected release. This applies only when the host uses the supported typed integration and wraps consequential boundaries.
Safe-harbor boundary
Test only the surface you are authorized to test.
The public arena authorizes bounded red-team attempts under its displayed rules. It does not authorize infrastructure attacks, service disruption, access to other users' data, provider abuse, or testing against unrelated systems. Stop and report privately if you encounter data exposure or a platform vulnerability.