Effective date: 29 July 2026
1. Purpose
We welcome good-faith reports that help protect authorised systems and users. This policy does not create an open-ended penetration-testing authorisation, bounty promise or permission to access data.
2. Contact
Send reports to [email protected] with the subject SECURITY REPORT. Do not include exploit code or personal information beyond what is necessary in the first message. We may provide a secure transfer method.
3. In-scope activity
Testing is in scope only where:
- it concerns a publicly accessible Enterprise Corporated system expressly identified as eligible;
- it uses the researcher's own Account and data;
- it is non-destructive and proportionate;
- it avoids automated volume that affects availability;
- it stops immediately if third-party, personal, confidential or restricted data is encountered; and
- the issue is reported promptly and kept confidential while remediation is assessed.
A current scope list must be published before active testing is invited. In the absence of an express scope list, only passive observation and non-invasive verification are authorised.
4. Prohibited research
Do not:
- access, modify, download, retain or disclose another person's data;
- use phishing, social engineering, credential stuffing or physical intrusion;
- perform denial-of-service, destructive, persistence, ransomware or malware testing;
- attack third-party providers, production dependencies or customer systems;
- bypass payment, licensing or account controls for benefit;
- threaten disclosure, demand payment or use coercion;
- publish before written coordination;
- degrade availability or consume unreasonable resources; or
- test from a jurisdiction or in a manner prohibited by law.
5. Reporting content
A useful report includes the affected URL or component, date and time, steps to reproduce, impact, prerequisites, screenshots or logs, and a safe remediation suggestion. Remove unnecessary personal information and secrets.
6. Our process
We aim to acknowledge a credible report within 5 business days, triage it according to severity, communicate material progress where practicable and coordinate remediation and disclosure. These are targets, not service-level guarantees.
We may request identity verification, a confidentiality undertaking, additional evidence or retesting. We decide whether and how to credit a researcher. No payment or reward is promised unless agreed in writing before or after assessment.
7. Good-faith treatment
Where a researcher complies with this policy, acts to avoid harm and reports promptly, our general position is not to pursue a complaint solely for that compliant research. This statement cannot bind third parties, regulators or law enforcement and does not protect conduct outside scope or contrary to law.
8. Security claims and cryptography
Reports should distinguish implemented controls from planned, experimental or marketing descriptions. A post-quantum-ready or algorithm-agile design is not equivalent to verified deployment of a post-quantum algorithm. Do not request or submit private keys.