Vulnerability disclosure policy
Last updated 29 August 2026
Reporting an issue
Email security@decisivecondition.com with enough detail to reproduce the issue — the affected URL or endpoint, the steps you took, and what you observed.
These details are also published at /.well-known/security.txt.
What we commit to
- We will acknowledge your report within five working days.
- We will tell you our assessment of the issue and whether we intend to fix it.
- We will credit you when a fix ships, if you would like us to.
We do not currently operate a paid bug bounty.
What we ask
- Give us a reasonable opportunity to fix an issue before disclosing it publicly.
- Do not access, modify or delete data belonging to anyone else. If you access another organisation's data unintentionally, stop and tell us what you saw.
- Do not run denial-of-service tests, automated scanning that degrades the service for others, or social engineering against our staff or suppliers.
Scope
In scope: this application and its API.
Out of scope: our suppliers' own infrastructure. Report those to the supplier directly — the providers we use are named in our privacy notice.
Findings that depend on a compromised end-user device, or on outdated browser versions no longer receiving security updates, are unlikely to be actionable.
Good faith
If you follow this policy when investigating and reporting an issue, we will treat your research as authorised, work with you to understand and resolve it quickly, and will not pursue or support legal action against you in relation to it.