Responsible Disclosure

At Accodeing to you, we consider the security of our systems a top priority. But no matter how much effort we put into system security, there can still be vulnerabilities present.

If you discover a vulnerability, we would like to know about it so we can take steps to address it as quickly as possible. We would like to ask you to help us better protect our clients and our systems.

For a vulnerability to be eligible for a reward you need to produce a workable POC that uses the vulnerability to access data that you should not have access to. If you are unsure if your vulnerability is eligible, please report it anyway and we will let you know.

For static sites placing a file in the root of the site is sufficient. For dynamic sites read access to the database is sufficient. For other types of vulnerabilities please contact us to discuss the requirements. If you think you could demonstrate an exploitable vulnerability but outside of these requirements please contact us to discuss and we’ll help you find a non-destructive way to demonstrate the vulnerability.

We do not reward

Results from automated tools or scans, missing security headers, missing security best practices, or reports indicating that the software is out of date. We are very probably aware of these issues and are are either working on them or have decided not to address them - with appropriate understanding of the risks from our end customer.

Security is, to some extent, a product of money and time. We have to balance the cost of security against the risk of a breach. We have made a decision to accept some risks and not to address some issues. Feel free to report them, but we will not reward them.

Please do the following

What we promise

We strive to resolve all problems as quickly as possible, and we would like to play an active role in the ultimate publication on the problem after it is resolved.


Originally written by Floor Terra and published under CC BY / Changed company name and contact information. Added pubkey link and fingerprint verification text. Changed the qualifying text for what reports are rewarded