Vulnerability Disclosure Policy

How to report a security issue to Infosecurs Limited — safely and responsibly.

Last updated: 24 July 2026

Our commitment

Security is at the heart of what we do. We value the work of security researchers and the wider community in helping keep Infosecurs, our customers and their people safe. If you have discovered a security vulnerability in our website or platform, we want to hear from you and will work with you to resolve it quickly.

How to report

Please email your findings to [email protected]. To help us triage and reproduce the issue quickly, please include:

  • A clear description of the vulnerability and its potential impact.
  • Step-by-step instructions to reproduce it (proof-of-concept, affected URLs, request/response details).
  • Any relevant screenshots, logs or supporting material.
  • How we can contact you for follow-up.

Machine-readable contact details are also published at /.well-known/security.txt in line with RFC 9116.

Scope

This policy applies to internet-facing systems and services operated by Infosecurs Limited, including infosecurs.com and our customer-facing platform. If you are unsure whether a system is in scope, please ask us before testing.

Out of scope

The following are generally not eligible and should not be reported as vulnerabilities:

  • Denial-of-service (DoS/DDoS), volumetric or resource-exhaustion attacks.
  • Social engineering, phishing or physical attacks against our staff, users or offices.
  • Reports from automated scanners without a demonstrated, exploitable impact.
  • Missing security headers, cookie flags or best-practice suggestions with no proven exploit.
  • Vulnerabilities affecting only unsupported or end-of-life browsers or platforms.
  • Third-party services we do not control (please report those to the relevant provider).

Guidelines for testing

When investigating a vulnerability, please:

  • Only interact with accounts you own or have explicit permission to test.
  • Avoid accessing, modifying, deleting or storing data that is not yours — use a proof-of-concept only to the extent needed to demonstrate the issue.
  • Not degrade, disrupt or interrupt our services or the experience of other users.
  • Give us a reasonable period to investigate and remediate before disclosing publicly, and coordinate any public disclosure with us.
  • Comply with all applicable laws.

Safe harbour

We will not pursue or support legal action against researchers who discover and report vulnerabilities in good faith and in accordance with this policy. We consider such activity to be authorised. If legal action is initiated by a third party against you for activity that was conducted in line with this policy, we will make this authorisation known.

What you can expect from us

  • We will acknowledge receipt of your report as soon as we reasonably can.
  • We will keep you informed as we investigate and work to remediate the issue.
  • We will treat your report confidentially and will not share your details without your permission.
  • Where you wish, and once an issue is resolved, we are happy to credit you for your responsible disclosure.

Reward

We do not currently operate a paid bug-bounty programme. We do, however, deeply appreciate responsible disclosure and are glad to offer public recognition to researchers who help us improve, with their consent.

Contact

Infosecurs Limited
Security reports: [email protected]
General enquiries: [email protected]