Responsible disclosure

Responsible disclosure

If you have found a security issue in anything we run, we want to hear about it. This page is the process.

How to report

Write to security@sirenbow.com. Include enough detail for us to reproduce the issue: affected URL or component, steps, and impact. Machine-readable contact details are at /.well-known/security.txt.

What to expect

  • We read every report. You get a human reply, not an auto-responder.
  • We tell you plainly whether we consider the report valid, and why.
  • If it is valid, we fix it and tell you when the fix is live. If you want credit, we give it.

Safe harbor

If you make a good-faith effort to follow this policy — no data destruction, no service disruption, no access beyond what is needed to demonstrate the issue — we will not pursue legal action against you for the research itself.

Out of scope

Denial-of-service testing, social engineering of our staff or clients, and physical testing are not covered by this policy. Reports about third-party systems should go to those vendors, not to us.

Our own disclosure practice

When we find issues in third-party systems during authorized work, we coordinate privately with the vendor first and publish only after a fix or an agreed deadline. Our published post-mortems cover incidents that are already public.