Legal
Responsible Disclosure
Last updated 7 September 2026
We test other people's systems for a living, so we take reports about our own seriously. If you have found a vulnerability in an innsecs system, here is how to tell us and what we commit to in return.
01How to report
Email security@innsecs.com with "Security" in the subject line. Please include enough detail for us to reproduce the issue: the affected asset, the steps taken, and the impact you believe it has.
Do not report vulnerabilities through the contact form, social media, or to individual employees. Please do not disclose the issue publicly before we have had a reasonable chance to fix it.
02What we commit to
- Acknowledge your report within 2 working days
- Provide an initial assessment within 5 working days
- Keep you updated on remediation progress
- Credit you publicly if you would like to be credited, once the issue is resolved
- Never pursue legal action against researchers who act in good faith under these terms
03Scope
In scope: systems and domains owned and operated by innsecs, including this website and our client-facing report delivery infrastructure.
Out of scope: any client system. Findings in a client environment discovered outside a contracted engagement must not be tested further, report them to us and we will route them appropriately.
04Please do not
- Access, modify or delete data that is not yours
- Perform denial-of-service or volumetric testing
- Use social engineering, phishing or physical attacks against our staff
- Run automated scanning at a rate that degrades service for others
- Demand payment in exchange for withholding disclosure
05Safe harbour
If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorised, will not initiate legal action against you, and will assist in making it known that your actions were conducted in compliance with this policy if a third party takes action.
If in doubt about whether something is in scope, ask us first.
06Rewards
We do not currently run a paid bug bounty programme. We do offer public credit, a genuine thank you, and a fast, respectful response, which is more than many programmes manage.
This document is provided as a starting point and does not constitute legal advice. Have it reviewed by a qualified lawyer in your jurisdiction before you rely on it.