1. Our Commitment
We take the security of traveller data seriously and welcome good-faith reports from security researchers. If you believe you have found a vulnerability on provenadventures.com or a related service, we want to hear from you before anyone else does.
2. How to Report
Email hello@provenadventures.com with the subject line “Security report”, including the affected URL or endpoint, steps to reproduce, and the impact you believe it has. Screenshots or proof-of-concept snippets help. Please give us a reasonable opportunity to remediate before any public disclosure.
3. Rules of Engagement
While testing: do not access, modify or delete other travellers' data; do not run denial-of-service or spam attacks; do not use social engineering against our staff; and stop and report immediately if you encounter personal data. Only test against accounts and data you own.
4. What to Expect
We acknowledge reports within three working days, keep you informed while we investigate and fix confirmed issues, and credit reporters who wish to be named. We do not pursue legal action against researchers who act in good faith within this policy.
Questions about this policy? Email hello@provenadventures.com or write to Proven Adventures, Jahazi Building, James Gichuru Road, Lavington, Nairobi, Kenya.
