Security

Reporting a vulnerability

Where to send it, what happens next, and what we commit to not doing to you. Last reviewed 2026-09-10.

Our commitments

What we will not do

No legal action

For research done in good faith under the rules below.

No police report

For a good-faith report.

No NDA to get a fix

Fixing it is not conditional on your silence.

No silent patching

We won't fix it quietly and deny it happened.

No naming without consent

Credit is yours to accept or decline.

No bug bounty — said plainly

There's no paid programme, and we won't imply one.

After you send it

What happens next

  1. Send it

    Email security@integrable.cloud with enough detail to reproduce it. A proof of concept helps; a video is fine. Please do not open a public issue first.
  2. We acknowledge within 3 working days

    A human reply confirming we have it and who is looking at it. If you do not hear back in that window, send it again — assume it was lost rather than ignored.
  3. We triage and tell you what we found

    Whether we could reproduce it, how we rate the severity, and roughly when a fix will ship. If we disagree with your severity assessment, we will say why rather than quietly downgrading it.
  4. We fix it and tell you it shipped

    Critical issues are worked immediately. Everything else gets a target date we will actually give you.
  5. We credit you, if you want

    Named on the incident write-up, or not, entirely your choice. We will not name you without asking.

The rules

Short, and the ordinary ones

  • Your own workspace only

    Test against your own data. Don't access, change or keep anyone else's.
  • No disruption

    No denial-of-service tests, spam, or social engineering of staff or customers.
  • Stop at proof

    Stop once you've shown the issue — don't pivot deeper to see how far it goes.
  • A fair window

    Give us time to fix it before publishing. If we're slow, tell us and we'll agree a date.

Worth reading before testing: the security architecture · incident history