Invarra

Security

Report a security issue to Invarra.

If you find a potential vulnerability in Phalanx or an Invarra website, send a high-level description through our security contact route. Include the affected product or page and enough context to understand the impact.

Start with a safe description.

Tell us what is affected, what you believe could happen, whether the behavior is repeatable, and how we can reply. Please keep credentials, private customer data, and exploit payloads out of the initial message. We can arrange a suitable channel for additional detail.

The execution boundary depends on the deployed route.

Phalanx controls enrolled actions whose credentials and execution paths sit behind the protected gateway. Authenticated task authority, current-state checks, policy, and one-use permits determine whether those actions may proceed.

The deployment must also close equivalent credentialed routes around that boundary. The surrounding application, host, identity systems, and configured external services remain part of the customer's security responsibilities.

Use the demonstration within its displayed rules.

The public demonstration is a guided product environment. Use the interactions it explicitly provides and follow its displayed instructions. It does not authorize infrastructure probing, service disruption, access to other users' data, or testing of unrelated systems.

If you encounter unexpected data exposure or a platform vulnerability, stop the interaction and report it privately.