Public evaluation draft
Security and Vulnerability Reporting
A production security-report channel, encryption option, scope, and response staffing must be verified before activation. No bug bounty is promised.
Status: Draft for counsel review before production activation.
Pre-launch and no-agreement notice
PUPMKT is a pre-launch product. Features, policies, listings, workflows, pricing, availability, and technical capabilities may be incomplete or change. Marketplace content and activity may be demonstration, curated, synthetic, or connector-ready and may not represent real transactions or operating services.
Access, review, testing, linking, or communication does not by itself create an agreement, partnership, agency, joint venture, confidentiality obligation, license, offer, commitment, exclusivity, acquisition arrangement, pilot, or other commercial relationship with Dravara, LLC. Any such relationship requires a separate written agreement executed by authorized representatives.
What this draft covers
- Reports should include affected route or component, reproducible steps, impact, and non-sensitive evidence.
- Good-faith research must avoid destructive testing, privacy invasion, persistence, service disruption, social engineering, or accessing data beyond what is necessary to demonstrate the issue.
- Urgent credential exposure requires a verified private channel; do not publish credentials or sensitive data. Receipt, triage, remediation, and status communications are operationally gated.
Review and activation gates
- Qualified counsel must approve the text, jurisdiction coverage, and release configuration.
- A published page does not activate a marketplace capability; matching technical and operational controls must be verified.
- Any provider, retailer, publisher, store, or other third-party relationship requires direct written authorization before it is described as active.
