Product security
We welcome good-faith security research that protects Sawoice users. This page explains the reporting channel, safe-harbor expectations, supported releases, and update policy.
Use the subject “Security report”. No public encryption key is claimed for this version; request a secure evidence channel first.
Email support@sawoice.com with the subject “Security report”. Include the affected product and version, reproducible steps, impact, and a safe proof of concept. Use a test account and minimize personal data.
Do not send secrets, access tokens, private audio, transcripts, database exports, or another person's data by ordinary email. Ask for a secure transfer method when sensitive evidence is necessary.
Where research follows these rules and applicable law, SAWANT CORE LLP intends to treat it as authorized good-faith testing and work toward a coordinated resolution. This statement cannot authorize conduct against a third party or override law.
We aim to acknowledge a credible report within three business days, assign severity and an owner, keep the reporter informed at meaningful milestones, and coordinate disclosure after a fix or mitigation. Complex provider, operating-system, or supply-chain issues can require additional time.
Security fixes are provided for the latest production website/API deployment and the latest generally available signed desktop release. Users should update promptly. Older desktop builds may be denied cloud/account access where necessary to protect users or infrastructure.
The exact production deployment and supported desktop build numbers are release evidence and must be published with each release; this policy does not invent versions that have not shipped.
Incidents are assessed against applicable CERT-In, GDPR/UK GDPR, US/state, Polar, and Cyber Resilience Act duties. We notify regulators, partners, or affected people when legally required and avoid publishing details that would increase active exploitation risk.