Responsible disclosure

Found something?
Tell us safely.

We welcome good-faith reports of suspected vulnerabilities affecting Sevenpoynt Security’s website or systems.

What to include

  • The affected URL, feature or service.
  • A clear description of the issue and likely impact.
  • Reproduction steps or a minimal proof of concept.
  • Any actions already taken and your preferred contact details.

Good-faith research

Keep testing proportionate and avoid accessing, changing or retaining data that is not your own. Do not degrade the service, use social engineering, perform denial-of-service testing or publicly disclose an unresolved issue.

Our commitment

We will acknowledge a credible report, investigate it, keep you informed where practical and work toward proportionate remediation. We will not pursue legal action against good-faith research that follows this policy.

Out of scope

Automated scanner output without demonstrated impact, clickjacking on pages without sensitive actions, missing headers without a credible exploit path and issues affecting unsupported third-party products should be reported to the relevant provider.