Caldrava Instruments of America
Security Reporting
Last updated August 10, 2026
Use the Caldrava request form to report a suspected vulnerability affecting CaldravaInstruments.com or an expressly identified Caldrava service. Choose “Security report.”
What to include
Provide the affected URL or service, observed behavior, reproducible steps, date and time, and a concise impact description. Do not include credentials, private keys, classified information, protected telemetry, personal records, or exploit payloads in the initial submission.
Responsible testing restrictions
Do not access or modify another person’s data; degrade availability; use social engineering, phishing, malware, denial of service, physical intrusion, or credential attacks; bypass third-party controls; or continue testing after encountering sensitive information. A public report does not grant authorization to test restricted systems.
Response
Submission does not create a bounty, contract, or promise of payment. Caldrava may request a secure follow-up channel, coordinate remediation, preserve audit evidence, and ask that publication be delayed while a verified issue is addressed.