Where to report

Email us at info@communicatevalues.com. A machine-readable contact is in /.well-known/security.txt.

What to send

What you found, how to reproduce it, and what you think it allows. Plain text is fine — no form needed.

How we respond

We confirm receipt within 5 working days and send you a first assessment within 10 working days. While a report is open we get back to you at least every 30 days. Once we have looked into it we tell you what we found and what we are doing about it. If we do not accept the finding, we say that too — and why.

Safe harbour

If you act in good faith under this page, we will not take legal action against you and we will work with you. Where that stops: it does not cover access to real people's data beyond the minimum needed as proof, nor copying, keeping or publishing it — and it cannot cover you against a third party whose systems you touch.

What is out of scope

Third-party systems we merely use (hosting, email, payments). Findings that need physical access to a user's device. Social engineering against us or our users. Never run load testing or DoS. We cannot accept or act on findings from these areas.

What we ask of you

Do not test on other people's accounts and do not download other people's data. If you run into them, stop and write to us.

Disclosure

We agree it with you. By default 90 days after the report, or sooner once a fix is deployed. If we miss the timelines above, we are not asking you to stay quiet.

Encryption

We do not offer a PGP key today. Until we do, do not email real people's data — send a description and we will agree on a channel.

What we do not promise

We do not pay bounties and we do not commit to a fix deadline — the timelines above are about our response, not the fix. We would rather say so than promise something we will not keep.

This page describes OUR PROCESS for vulnerability reports. It makes no claim of conformity with any standard, nor that any standard does not apply to us.

Back to sign-in