Legal and regulatory framework

Security And Responsible Disclosure Policy

Effective date: 29 July 2026

1. Purpose

We welcome good-faith reports that help protect authorised systems and users. This policy does not create an open-ended penetration-testing authorisation, bounty promise or permission to access data.

2. Contact

Send reports to [email protected] with the subject SECURITY REPORT. Do not include exploit code or personal information beyond what is necessary in the first message. We may provide a secure transfer method.

3. In-scope activity

Testing is in scope only where:

A current scope list must be published before active testing is invited. In the absence of an express scope list, only passive observation and non-invasive verification are authorised.

4. Prohibited research

Do not:

5. Reporting content

A useful report includes the affected URL or component, date and time, steps to reproduce, impact, prerequisites, screenshots or logs, and a safe remediation suggestion. Remove unnecessary personal information and secrets.

6. Our process

We aim to acknowledge a credible report within 5 business days, triage it according to severity, communicate material progress where practicable and coordinate remediation and disclosure. These are targets, not service-level guarantees.

We may request identity verification, a confidentiality undertaking, additional evidence or retesting. We decide whether and how to credit a researcher. No payment or reward is promised unless agreed in writing before or after assessment.

7. Good-faith treatment

Where a researcher complies with this policy, acts to avoid harm and reports promptly, our general position is not to pursue a complaint solely for that compliant research. This statement cannot bind third parties, regulators or law enforcement and does not protect conduct outside scope or contrary to law.

8. Security claims and cryptography

Reports should distinguish implemented controls from planned, experimental or marketing descriptions. A post-quantum-ready or algorithm-agile design is not equivalent to verified deployment of a post-quantum algorithm. Do not request or submit private keys.