Security
Avelir, a VPN client published by AdaptGroup LLC
Last updated August 29, 2026
How to report a vulnerability, what we promise in return, and how long each version is supported. This page is in English only: a disclosure policy carries deadlines and a promise not to take legal action, and a machine translation of those is worse than none.
Reporting a vulnerability
Write to [email protected].
Tell us what you found, which version and platform you saw it on, and what an attacker could do with it. A proof of concept helps and is never required.
What happens next
- We acknowledge every report within 3 working days. If you do not hear back, assume the mail was lost and write again.
- We tell you our assessment — whether we consider it a vulnerability, and how severe — within 10 working days.
- We aim to ship a fix within 90 days of the report, sooner when the issue is being exploited.
- We publish what was fixed once the fix is available, and we credit you by the name you choose, or not at all if you prefer.
We will not take legal action against anyone who reports a vulnerability to us in good faith, who does not access, modify or delete other people’s data, and who does not disrupt our services or those of our partners while investigating.
Scope
In scope: the Avelir application on all platforms, its installers and packages, the Windows service avelir-daemon, the Linux daemon, and the website avelir.app.
Out of scope: the servers of VPN providers whose subscriptions people use with Avelir. We do not run them and cannot act on reports about them — report those to the provider. Third-party components (Xray-core, libXray, Wintun) should be reported to their own projects; tell us as well if Avelir is affected, and we will carry it forward and ship the fix.
How long we support a version
We provide security fixes for five years from the release of each version. This is the support period within the meaning of Regulation (EU) 2024/2847 (Cyber Resilience Act).
How updates reach you
Builds installed from Google Play or the App Store are updated by the store.
Builds installed from avelir.app, GitHub Releases or the Windows installer check https://avelir.app/version.json over HTTPS and tell you when a newer version exists; they never install anything by themselves. Every build published outside the stores carries its SHA-256 next to it.
Software bill of materials
Every release carries avelir-<version>-sbom.cdx.json, a CycloneDX bill of materials covering the components linked into the shipped binaries. The same information in readable form is in THIRD-PARTY-NOTICES.md, shipped with every build and listed inside the app.
Contact
AdaptGroup LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA.