Security policy and vulnerability disclosure
Eyva — Security Policy and Vulnerability Disclosure
We want to hear about security problems in Eyva™. This page says how to tell us, what we promise in return, and what is in scope. It is published at https://conserius.com/security.
How to report
Write to security@conserius.com.
Please include:
- what the problem is and what an attacker could do with it;
- the steps to reproduce it, and the Eyva version (Eyva ▸ Settings ▸ About shows it) and macOS version;
- any proof-of-concept, logs or screenshots — with your own personal data removed.
We do not publish an encryption key at this time; if your report is sensitive, say so in a first message without the details and we will agree a way to receive them.
What we promise
- We confirm we received your report within 3 working days.
- We tell you whether we can reproduce it, and our plan, within 10 working days.
- We keep you updated until it is fixed, and we tell you before we publish anything about it.
- We credit you by name in the release notes if you want us to.
- We will not take legal action against you for research that follows this policy in good faith.
We do not run a paid bug bounty at this time.
Please do
- Test only against your own copy of Eyva and your own account.
- Stop and tell us as soon as you reach data that is not yours.
- Give us a reasonable time to fix the problem before you disclose it — we aim for 90 days, and we will agree a date with you.
Please don't
- Access, change or delete anyone else's data, or keep more of it than you need to show the problem.
- Disrupt our relay or degrade the service for others (no load or denial-of-service testing).
- Use social engineering, phishing or physical attacks against us, our users or our providers.
- Test the systems of our providers (Anthropic, Cloudflare, Stripe and the others named in the Privacy Policy). Report problems in their systems to them.
In scope
- The Eyva app for macOS, including its signed helper programs.
- Eyva's protections: the path guard, the approval tiers, the privacy veil, the outbound-destination list, and the record of what was sent.
- Our cloud relay and account service.
- Our website, conserius.com.
Out of scope
- Problems that need an attacker to already control your Mac or your macOS user account.
- Reports produced only by automated scanners, without a demonstrated impact.
- Missing best-practice headers or settings with no demonstrated impact.
- Problems in third-party services, models or open-source components that are not caused by how Eyva uses them (please report those upstream; tell us too if Eyva is affected).
How we handle a confirmed vulnerability
We fix it, ship an update, and say in the release notes what was fixed. If personal data was put at risk, we follow our incident procedure, which includes telling affected people and the authorities where the law requires.
The EU Cyber Resilience Act. Eyva is software sold with digital elements, so we treat the Act as applying to it. Its reporting duty applies from 11 September 2026: an actively exploited vulnerability or a severe incident is reported through ENISA's single reporting platform — an early warning within 24 hours and a notification within 72 hours. Its main obligations apply from 11 December 2027. This vulnerability-handling process and the security contact above are part of meeting it.
Thanks
People who have reported a problem and asked to be credited are listed here. (None yet.)
© 2026 Conserius Inc. Eyva™ is a trademark of Conserius Inc.