Our commitments
What we will not do
No legal action
For research done in good faith under the rules below.
No police report
For a good-faith report.
No NDA to get a fix
Fixing it is not conditional on your silence.
No silent patching
We won't fix it quietly and deny it happened.
No naming without consent
Credit is yours to accept or decline.
No bug bounty — said plainly
There's no paid programme, and we won't imply one.
After you send it
What happens next
Send it
Email security@integrable.cloud with enough detail to reproduce it. A proof of concept helps; a video is fine. Please do not open a public issue first.We acknowledge within 3 working days
A human reply confirming we have it and who is looking at it. If you do not hear back in that window, send it again — assume it was lost rather than ignored.We triage and tell you what we found
Whether we could reproduce it, how we rate the severity, and roughly when a fix will ship. If we disagree with your severity assessment, we will say why rather than quietly downgrading it.We fix it and tell you it shipped
Critical issues are worked immediately. Everything else gets a target date we will actually give you.We credit you, if you want
Named on the incident write-up, or not, entirely your choice. We will not name you without asking.
The rules
Short, and the ordinary ones
Your own workspace only
Test against your own data. Don't access, change or keep anyone else's.No disruption
No denial-of-service tests, spam, or social engineering of staff or customers.Stop at proof
Stop once you've shown the issue — don't pivot deeper to see how far it goes.A fair window
Give us time to fix it before publishing. If we're slow, tell us and we'll agree a date.
Worth reading before testing: the security architecture · incident history