Reporting a security problem
If you have found a security problem in this service, this page says how to tell us and what happens after you do.
What this covers
This policy covers scopeward.eu, app.scopeward.eu, and the application served on them.
It does not cover the systems run by the providers this deployment depends on. Those are named on the page about how this service is run, and a problem in one of them goes to the provider concerned.
It does not cover a customer's own product. This service makes no finding about how anybody's product is built.
How to report
Send reports to security@scopeward.eu
Write in English. Say what you did, what you saw, and where — the address or endpoint, the steps, and the result.
A short worked example is worth more than a scanner export. Send the export too if you have one.
Do not put anybody else's personal data in the report. Describe it instead.
What we ask while you are looking
Test against accounts and data that are your own. Do not read, change or keep anybody else's.
If you come across personal data by accident, stop at that point and say so in your report.
Do not degrade the service for other people: no load testing, no denial-of-service testing, and no automated scanning heavy enough to matter.
Leave people out of it. No phishing, no pretexting, no approaches to staff or to any provider, and nothing physical.
Give us ninety days to ship a fix before you publish. If we need longer we will say so, and say why.
What we will not do
If you keep to this policy, we will not bring or support legal or law-enforcement action against you over the research itself.
That is our own position and it binds only us. It cannot waive the rights of a customer, of a provider, or of anybody else, and it is not advice about the law where you are.
What happens after you send it
We aim to acknowledge a report within five days of receiving it.
After that we say what we intend to do about it, and we tell you when a fix has shipped.
If we decide the report is not something we will act on, we say that too, and why.
If you would like to be named once a fix is out, say so in your report.
There is no bounty
This service does not pay for security reports and does not run a paid disclosure programme. Sending a report creates no claim to payment.
Nothing on this page offers a reward, and nothing here should be read as one.