Trust & security · Disclosure

Report a vulnerability.

If you have found a security issue in this website or anything Accurith operates, thank you for taking the time to tell us. Send enough detail to reproduce it.

01

Where to send it

One address, monitored by a practitioner.

A machine-readable security.txt (RFC 9116) accompanies this policy on the production site, at /.well-known/security.txt. General enquiries go to [email protected] instead — this address is for security reports.

02

What we undertake

What you can expect from us.

  • We will acknowledge your report within two business days.
  • We will not pursue legal action for good-faith research that respects user data and service availability.
  • We will keep you informed as we validate and fix the issue, and credit you if you would like.

03

Out of scope

What we ask you not to do.

Good-faith research has edges. These are ours — staying inside them is what keeps the undertaking above unconditional.

  • Testing against production data, or accessing another person’s records.
  • Denial of service, volumetric testing, or anything that degrades availability for other visitors.
  • Social engineering of our people, our clients, or our suppliers.
Please give us a reasonable window to fix an issue before publishing it. We would rather coordinate a disclosure with you than read about it at the same time as everyone else.