SECOMPSSECOMPS
Home/Responsible Disclosure
Legal

Responsible disclosure.

If you have found a security issue in a SECOMPS system, we want to hear about it and we will not take legal action against good-faith research.

Scope

Systems operated by SECOMPS at our own domains. Client systems we have tested are explicitly out of scope: report those directly to the organisation concerned.

How to report

Email security@secomps.com with enough detail to reproduce the issue. Encrypt sensitive detail using a key we will provide on request if you prefer.

What we commit to

Acknowledgement within [SPECIFY] working days, an assessment and an indication of timeline, updates until resolution, and public credit if you would like it.

We will not pursue legal action for good-faith research that respects this scope, avoids privacy violations and service degradation, and gives us reasonable time to remediate before disclosure.

Out of scope

Denial of service, social engineering of our staff, physical attacks, and findings from automated scanners with no demonstrated impact.

Placeholder notice. This page is a structural draft. Have it reviewed by qualified legal counsel in your jurisdiction before publishing.