# Vulnerability Report Template

Thank you for helping us keep Vistaan and our customers safe. Please use the structure below to make sure we can act on your report quickly.

## Summary
A one or two sentence description of the vulnerability.

## Severity (your estimate)
- [ ] Critical
- [ ] High
- [ ] Medium
- [ ] Low

## Affected component(s)
URL, endpoint, or feature:

## Steps to reproduce
1. ...
2. ...
3. ...

## Observed behaviour
What happens:

## Expected behaviour
What should happen:

## Impact
Who is affected and how (data, accounts, availability, etc.):

## Environment
- Date observed:
- Browser / client (if applicable):
- Account type (if applicable):

## Suggested fix (optional)
If you have a recommendation, share it here.

## Contact (optional)
- Name:
- Preferred contact (email / Signal handle):

---

Send the completed report to security@vistaan.com. If the report contains
sensitive details, encrypt with our PGP key (fingerprint 3F4A 8C9B 21D6
7E05 9A11 6B22 4D88 7E33 0C55 91AB). We acknowledge reports within 2
business days and follow up with a triage update within 5 business days.
