Email us at info@communicatevalues.com. A machine-readable contact is in /.well-known/security.txt.
What you found, how to reproduce it, and what you think it allows. Plain text is fine — no form needed.
We confirm receipt within 5 working days and send you a first assessment within 10 working days. While a report is open we get back to you at least every 30 days. Once we have looked into it we tell you what we found and what we are doing about it. If we do not accept the finding, we say that too — and why.
If you act in good faith under this page, we will not take legal action against you and we will work with you. Where that stops: it does not cover access to real people's data beyond the minimum needed as proof, nor copying, keeping or publishing it — and it cannot cover you against a third party whose systems you touch.
Third-party systems we merely use (hosting, email, payments). Findings that need physical access to a user's device. Social engineering against us or our users. Never run load testing or DoS. We cannot accept or act on findings from these areas.
Do not test on other people's accounts and do not download other people's data. If you run into them, stop and write to us.
We agree it with you. By default 90 days after the report, or sooner once a fix is deployed. If we miss the timelines above, we are not asking you to stay quiet.
We do not offer a PGP key today. Until we do, do not email real people's data — send a description and we will agree on a channel.
We do not pay bounties and we do not commit to a fix deadline — the timelines above are about our response, not the fix. We would rather say so than promise something we will not keep.
This page describes OUR PROCESS for vulnerability reports. It makes no claim of conformity with any standard, nor that any standard does not apply to us.