Legal
Responsible disclosure
We welcome good-faith security research. If you find a vulnerability in an ENI6MA property or a shipping component you can safely test, tell us before you publish.
How to report
- Email security@eni6ma.com with a clear description, steps to reproduce, and impact as you understand it.
- Give us a reasonable window to investigate before public disclosure.
- Avoid accessing other customers’ data, destroying data, or degrading availability.
What we ask
Stay within the law. Do not coerce or threaten. We will acknowledge receipt, keep you updated when we can, and credit researchers who want credit once a fix ships, unless you prefer to stay anonymous.
Out of scope (for this page)
Social engineering of staff, physical intrusion, and attacks on third-party services we do not control. Demo packs you run locally are yours to exercise with Verify; please still report issues that would affect shared public infrastructure.
