Contact
Every question about Eva is answered in public, on the issue tracker.
Questions, bugs, and requests
A question answered in public is answered once, and the next person who asks it finds the answer instead of asking it again. That is why there is an issue tracker and not a support address.
Include the version from `eva --version`, the command you ran, and what happened instead. Eva prints findings to stderr without changing the exit code, so paste stderr as well as stdout.
Security
There is no separate security mailbox. Report a suspected vulnerability as an issue that says what the impact is and which code path reaches it, and leave a working exploit out of the first message.
If the finding needs to stay private until it is fixed, say so in the first line rather than in the detail, and a private channel will be opened before anything more is written down.
Changes to the program
The source takes patches. Read the contributing page in the documentation first: it names the commit format, the branch naming, and the checks a change has to pass.
Every release is published with its notes, its checksums, and a provenance attestation.
The company
Missing studio publishes Eva. Its other work is on the same organisation, and it posts as @madebymissing.