Vowli LLC / Security & disclosure
Security is
a practice.
Clear boundaries. Direct accountability. A responsible way to do technically demanding work.
Operational controls
Vowli LLC is an owner-operated software engineering and security research company. The following statements describe the owner-managed practices used for our work.
Verified identity. Direct accountability.
Vowli is owner-operated, with identity and KYC documentation held in connection with the LLC. One accountable operator oversees the work.
Identity documentation is shared through the appropriate private verification process, never published on this website.
Hardware-backed access.
Physical hardware security keys protect the owner’s privileged accounts. Administrative access stays under the owner’s direct control.
Access is limited to the accounts and environments needed for the authorized work. Credentials are kept separate from research artifacts.
Isolated research. Human oversight.
Advanced research and model-assisted testing run in isolated, non-production environments, with the owner reviewing scope and approving sensitive actions.
Research isolation is a technical boundary. A model’s output does not grant permission to reach additional systems or expand a test.
Explicit authorization. Responsible disclosure.
Work is restricted to legally authorized scopes, including public and private bug bounty programs. The owner personally handles disclosure and maintainer coordination.
Program rules and agreed boundaries determine permitted activity. Findings are handled privately while affected maintainers assess and remediate them.
Authorization comes first.
Research is limited to systems we own or have explicit authorization to assess. Where work is conducted under a bug bounty program, its scope, exclusions, and disclosure requirements govern the work.
AI-assisted research remains subject to the same boundaries. A generated instruction or finding does not expand authorization. Sensitive actions require the owner’s review, and advanced testing stays in isolated, non-production environments.
This statement describes our operating practices. It is not a claim of independent security certification or approval by a model provider.
Report a vulnerability.
If you believe you have found a security issue affecting Vowli or Skinli, contact [email protected] with the subject “Security disclosure”. The owner handles reports directly.
- Identify the affected domain, application, and version, if known.
- Describe the issue and the minimum steps needed to reproduce it.
- Share the likely impact and your preferred way to be contacted.
- Arrange a secure handoff before sending credentials, personal data, or sensitive artifacts.
This reporting channel does not grant authorization to test third-party infrastructure, access another person’s data, or perform disruptive testing. Any separate research authorization must be agreed explicitly.
Contact us about a security issuePublic PGP key
A public PGP key has not been published yet. Contact us to arrange a secure reporting channel and verify the key fingerprint before sharing sensitive material.
Arrange a secure handoff