Security
Vulnerability disclosure
Last updated: October 10, 2026
Security is our profession, and we hold our own systems to the standard we apply for our clients. If you believe you have found a security vulnerability in a website or service operated by SecSmithOps, we want to hear about it and we will work with you to resolve it.
How to report
Email contact@secsmithops.com with the subject “Security report”. Please include:
- The affected URL or component and the type of issue
- Step-by-step instructions to reproduce it
- The impact you believe it has
- Any proof-of-concept, kept to the minimum needed to demonstrate the issue
- How we can reach you for follow-up questions
What to expect
- An acknowledgement of your report within three business days
- Updates as we investigate and remediate
- Credit for your finding once it is resolved, if you would like it
Scope
In scope: secsmithops.com and services operated by SecSmithOps. Out of scope: denial-of-service or load testing, social engineering, physical attacks, spam, findings in third-party services we use, and automated scanner output without a demonstrated security impact.
Guidelines
- Only test against accounts and data you own or have explicit permission to use
- Do not access, modify, or retain data that does not belong to you; stop and report as soon as you encounter it
- Do not degrade the availability of our services
- Give us reasonable time to fix the issue before any public disclosure
Safe harbor
We will not pursue legal action against researchers who act in good faith and follow this policy. We do not currently run a paid bug bounty program.
Machine-readable contact details are published at /.well-known/security.txt.