Legal
Responsible Disclosure
Last updated: September 29, 2026 · Effective for securityposture.dev
1. Purpose
We welcome reports of security vulnerabilities that affect SecurityPosture’s website, APIs, or customer data. This policy describes how to report issues so we can investigate and remediate responsibly.
2. How to report
Email security@securityposture.dev with:
- A clear description of the issue and potential impact
- Steps to reproduce, including affected URLs or endpoints
- Any proof-of-concept limited to demonstrating the issue
- Your contact details for follow-up
3. Guidelines
- Do not access or modify data that is not yours
- Do not perform destructive testing or denial-of-service attacks
- Do not publicly disclose the issue until we have confirmed a fix or agreed on a disclosure timeline
- Act in good faith and within applicable law
4. What is out of scope
- Social engineering of SecurityPosture staff or customers
- Physical attacks against infrastructure
- Reports from automated scanners without a demonstrated impact
- Issues in third-party services outside our control
5. Our commitment
We will acknowledge valid reports in a reasonable timeframe, keep you informed where practical, and will not pursue legal action against researchers who follow this policy in good faith. We do not currently operate a paid bug bounty; recognition may be offered at our discretion.
6. Contact
Security contact: security@securityposture.dev. General inquiries: hello@securityposture.dev.
Security · Security · Scan a domain · Home