SecSmithOps

Security

Vulnerability disclosure

Last updated: October 10, 2026

Security is our profession, and we hold our own systems to the standard we apply for our clients. If you believe you have found a security vulnerability in a website or service operated by SecSmithOps, we want to hear about it and we will work with you to resolve it.

How to report

Email contact@secsmithops.com with the subject “Security report”. Please include:

  • The affected URL or component and the type of issue
  • Step-by-step instructions to reproduce it
  • The impact you believe it has
  • Any proof-of-concept, kept to the minimum needed to demonstrate the issue
  • How we can reach you for follow-up questions

What to expect

  • An acknowledgement of your report within three business days
  • Updates as we investigate and remediate
  • Credit for your finding once it is resolved, if you would like it

Scope

In scope: secsmithops.com and services operated by SecSmithOps. Out of scope: denial-of-service or load testing, social engineering, physical attacks, spam, findings in third-party services we use, and automated scanner output without a demonstrated security impact.

Guidelines

  • Only test against accounts and data you own or have explicit permission to use
  • Do not access, modify, or retain data that does not belong to you; stop and report as soon as you encounter it
  • Do not degrade the availability of our services
  • Give us reasonable time to fix the issue before any public disclosure

Safe harbor

We will not pursue legal action against researchers who act in good faith and follow this policy. We do not currently run a paid bug bounty program.

Machine-readable contact details are published at /.well-known/security.txt.