What this policy covers
This policy covers the Security Inspect website and other systems that Security Inspect operates for itself. It doesn't cover our clients' systems, and it doesn't authorize anyone to test them.
That includes the public website at securityinspect.com. This page is only for reporting security problems in our own systems. It isn’t a way to request services, such as a penetration test or PCI DSS readiness: for those, use the contact page and choose the service you need.
How to report
Every inquiry starts with the contact form on this website, including security vulnerability reports and privacy requests. We don't publish an email address, phone number, or postal address.
Send your report through our contact form and choose “Report a security vulnerability” as the topic.
- Please write in English.
- Send one report per issue, so each fix can be tracked on its own.
- Do not send passwords, authentication codes, payment-card data, health information, controlled information, exploit material, or assessment evidence through this form. If sensitive material becomes necessary, we will agree an appropriate transfer method before you send it.
What to include
A clear report helps us confirm the problem quickly. Where you can, include:
- A short description of the issue and the kind of weakness it is, such as broken access control.
- The affected page, address, or component.
- Step-by-step instructions to reproduce it, including any tools or settings you used.
- What someone could do with it, as far as you’ve been able to confirm.
- A description, in words, of a minimal proof of concept that shows the issue without exposing anyone else’s information. If we need the proof of concept itself, we’ll agree how you can send it.
- The email address we should use for follow-up questions, in the form’s email field.
If you came across passwords, personal information, or other sensitive data, don’t include it in your report. Describe what you saw and where instead.
Out of scope
The following aren’t covered by this policy, and you shouldn’t attempt them:
- Denial-of-service or load testing, or anything else that slows or interrupts a service.
- Social engineering, including phishing, of our team, our contractors, or our clients.
- Physical testing of any location, device, or person.
- Spam, or flooding our forms.
- Services run by third parties, such as hosting or email providers. Report those to the provider under its own policy.
- Output from automated scanners without a demonstrated impact.
Rules for research
- Only test systems this policy covers.
- Don’t access, copy, change, or delete information that isn’t yours. Take only the minimum needed to show the issue exists, such as a screenshot that shows access is possible, not the data itself.
- Respect privacy. If you reach personal or confidential information, stop, don’t keep it, and tell us.
- Don’t use a vulnerability to reach other systems or keep access over time.
- Stop testing and report to us as soon as you’ve confirmed an issue.
- Delete anything you obtained once you’ve reported it, unless we ask you to keep it while we investigate.
- Follow applicable U.S. law.
What you can expect from us
- We review vulnerability reports during our published business hours and acknowledge them as soon as practicable. We don't publish a fixed response time.
- After we acknowledge your report, we'll tell you whether we could confirm the issue, keep you updated while we work on a fix, and let you know when it's resolved.
Good-faith research
When you act in good faith and within this policy, we treat your research as authorized, and we won't bring or support legal action against you because of it. We can't authorize testing of systems that other companies own or operate, including services we use.
Rewards
We don't run a bug bounty program, and we don't pay for vulnerability reports.
Coordinated disclosure
Please keep the details of a vulnerability private until we've fixed it or we've agreed on a disclosure date with you.
If you plan to write or speak about what you found, tell us first so we can agree on the timing and check that nothing sensitive is included.
Machine-readable contact
Our security contact and a link to this policy are also published in the standard format described in RFC 9116, the security.txt standard.
Contact: https://securityinspect.com/contact#security-reportExpires: 2027-03-26T00:00:00.000ZPolicy: https://securityinspect.com/assurance/responsible-disclosurePreferred-Languages: enCanonical: https://securityinspect.com/.well-known/security.txt