Report Security Issue
If you find a possible security weakness affecting Achevy or our website, please let us know as soon as you can.
We take legitimate security reports seriously and review verified issues promptly. Our aim is to investigate responsibly, protect our customers, and address confirmed vulnerabilities as quickly as reasonably possible.
Please review the guidelines below before submitting a report.
SECTION 1 – CORE PRINCIPLES
Achevy does not intend to pursue legal action against individuals conducting security research in good faith who follow the guidelines set out in this policy.
We ask that you:
1. Allow Reasonable Time
Give us sufficient time to investigate a reported issue and address it before sharing information about it publicly.
2. Respect User Privacy
Do not access, collect, change, or retrieve other users’ personal information without their permission.
3. Act in Good Faith
Your testing must not lead to privacy violations, service interruptions, data loss, damage, or unnecessary disruption for our customers or systems.
4. Do Not Exploit Vulnerabilities
Do not exploit a discovered vulnerability to obtain unauthorized access to sensitive information, elevate privileges, or introduce additional security risks.
Limit testing to what is reasonably necessary to demonstrate the issue.
5. Follow Applicable Laws
All security research must comply with applicable laws and regulations.
SECTION 2 – SECURITY REPORTS AND REWARDS
Achevy values responsible security researchers who help identify legitimate vulnerabilities.
In certain cases, Achevy may offer a reward for a security report that is both valid and meaningful. The decision to provide any reward rests entirely with Achevy and may be influenced by the issue’s severity, its potential impact, the report’s quality, and whether the vulnerability was already known.
To qualify for a reward, you must:
- Follow Our Core Principles
Meet every requirement set out in Section 1. - Report a Genuine Security Vulnerability
The issue must pose a meaningful security or privacy risk to Achevy, our systems, or our customers. - Report the Issue Directly to Achevy
Please use the contact information provided below to submit your report instead of reaching out to individual employees. - Report Accidental Access Immediately
If you unintentionally access personal information or confidential data, or cause a service disruption, stop testing and notify us right away.
Submitting a report does not automatically make it eligible for compensation.
SECTION 3 – NON-ELIGIBLE SUBMISSIONS
The following reports generally do not qualify for rewards:
- Spam, phishing, or social engineering reports that are unrelated to Achevy’s infrastructure
- Missing SPF, DKIM, or DMARC records when no security impact has been demonstrated
- Clickjacking on pages without sensitive actions
- Rate-limiting or brute-force concerns that do not create a meaningful security impact
- Denial-of-Service (DoS) or Distributed Denial-of-Service (DDoS) testing
- Issues requiring a rooted or jailbroken device
- Vulnerabilities affecting outdated or unsupported browsers, software, or extensions
- Automated scanner findings that show no evidence of an actual security impact
- Cosmetic issues or general website bugs that do not pose a security or privacy risk
HOW TO SUBMIT A SECURITY REPORT
Please send security-related reports to:
✉ Email: Contact@achevy.com
To help us investigate the issue efficiently, include as much relevant information as possible, including:
- Clear steps for reproducing the issue
- A description of its potential security impact
- The affected page, feature, or URL
- Relevant screenshots
- Relevant code snippets or other technical details
- Any additional information that could help us reproduce and understand the issue
Please do not include other users’ personal information unless it is absolutely necessary to explain the vulnerability.
CONTACT INFORMATION
📱 Phone: +1 (229) 466-1172
✉ Email: Contact@achevy.com
📍 Address: 120 E 5th St, Ocilla, GA 31774, USA


