Legal

Security Policy

How to report a vulnerability and what we commit to in return.

Reporting

Email [email protected] with the words "Security Report" in the subject. Include steps to reproduce and the impact you observed.

What we ask

Give us reasonable time to fix an issue before disclosing it publicly. Do not access, modify or delete data belonging to other customers. Do not run denial-of-service tests or automated scanners against production.

What we do

We acknowledge reports, investigate, and fix confirmed issues as a priority. We will tell you when a fix is deployed.

Safe harbour

Good-faith research that follows this policy will not lead to legal action from us.

No bounty programme yet

We do not currently operate a paid bug bounty. Reports are still very welcome.

Operated by Mahad Information Technology. Last updated 2026-10-01.