Caldrava Instruments of America

Security Reporting

Use the Caldrava request form to report a suspected vulnerability affecting CaldravaInstruments.com or an expressly identified Caldrava service. Choose “Security report.”

What to include

Provide the affected URL or service, observed behavior, reproducible steps, date and time, and a concise impact description. Do not include credentials, private keys, classified information, protected telemetry, personal records, or exploit payloads in the initial submission.

Responsible testing restrictions

Do not access or modify another person’s data; degrade availability; use social engineering, phishing, malware, denial of service, physical intrusion, or credential attacks; bypass third-party controls; or continue testing after encountering sensitive information. A public report does not grant authorization to test restricted systems.

Response

Submission does not create a bounty, contract, or promise of payment. Caldrava may request a secure follow-up channel, coordinate remediation, preserve audit evidence, and ask that publication be delayed while a verified issue is addressed.

Open the request form

Return to Caldrava Instruments