Elysian processes commercial insurance claims on behalf of carriers and their policyholders. Protecting that data is core to our business, and we value the work of security researchers who help us do it.
If you believe you've found a vulnerability in an Elysian system, we want to hear from you. This page explains what's in scope, how to report, and what you can expect from us.
How to report
Email security@elysian.is with:
- A description of the vulnerability and its potential impact
- Step-by-step reproduction instructions (proof-of-concept code, screenshots, or request/response logs are welcome)
- The URL, endpoint, or component affected
- Your contact details, if you'd like credit or follow-up
You may report anonymously. If you prefer encrypted communication, request our PGP key in your first message.
What to expect from us
- Acknowledgment within 2 business days of your report
- An initial assessment within 10 business days, including whether we've confirmed the issue
- Ongoing updates until the issue is resolved
- Credit on this page (with your permission) for valid, previously unknown vulnerabilities
- Rewards at our discretion for high-impact findings, based on severity and quality of the report
Scope
In scope
- elysian.is and all subdomains
- elysiantpa.com and all subdomains
- The Elysian claims platform and its APIs
Out of scope
- Third-party services we use (report those to the vendor)
- Denial-of-service or resource-exhaustion testing
- Social engineering, phishing, or physical attacks against Elysian employees, offices, or claimants
- Spam, SPF/DKIM/DMARC configuration reports without a demonstrated exploit
- Clickjacking on pages with no sensitive actions
- Reports from automated scanners without a validated, reproducible finding
Rules of engagement
Because our systems handle insurance claims data, we ask that you:
- Stop immediately and report if you gain access to any personal, claims, or policyholder data. Do not download, copy, or share it beyond the minimum needed to demonstrate the issue.
- Test only against accounts you own or have created for testing
- Do not degrade service availability or destroy data
- Do not publicly disclose the vulnerability before we've had a reasonable opportunity to remediate — we ask for 90 days from your report, and we'll work with you on coordinated disclosure
Safe harbor
If you make a good-faith effort to comply with this policy, we will consider your research authorized, will not initiate legal action against you, and will not refer you to law enforcement for your research. If a third party takes legal action against you for activity conducted in accordance with this policy, we will make it known that your actions were authorized.
Questions about this policy? Contact security@elysian.is.