Trust
Security
Last updated:
Our clients trust us with their code, their infrastructure and sometimes their users' data. This page summarizes how we protect that trust and how to tell us about a security issue.
How we work
Accounts and access
- Multi-factor authentication is required on every account we use for business.
- We follow least privilege: people and systems get only the access they need, and we remove access when it is no longer needed.
- Client credentials are stored in a password manager, never in email, chat or source code.
Development
- Changes go through code review before they reach production.
- We monitor dependencies for known vulnerabilities and keep them up to date.
- Secrets are kept out of source control and managed with the platform's secret storage.
- We keep development, staging and production environments separate.
Data
- Data is encrypted in transit with TLS, and we use providers that encrypt data at rest.
- We only access and keep the client data we need for the work, and handle it as set out in our agreement with each client.
- If we become aware of a security incident affecting a client, we notify them promptly.
This website
This site is static: it has no database, no forms, no accounts and no server-side code. It is served only over HTTPS, with a strict Content Security Policy and other security headers.
Vulnerability disclosure policy
We welcome reports from security researchers and anyone else who finds a potential vulnerability. If you report in good faith and follow this policy, we will work with you to understand and fix the issue quickly.
How to report
Email security@example.com with:
- a description of the issue and its potential impact;
- the URL or component affected;
- step-by-step instructions to reproduce it, including any proof-of-concept code; and
- how you would like to be credited, if at all.
Our contact details are also published in/.well-known/security.txt.
Scope
In scope:
- this website, www.example.com; and
- other domains and services owned and operated by [LEGAL ENTITY NAME].
Out of scope:
- Software and systems we built for clients. These are owned by our clients, so please report issues to them directly. If you believe an issue affects work we did, you may also tell us, and we will coordinate with the client.
- Third-party services we use, such as Cloudflare or our email provider. Report those to the vendor.
- Denial-of-service attacks, social engineering, physical attacks, and reports from automated scanners without a demonstrated, exploitable impact.
Safe harbor
If you make a good-faith effort to follow this policy, we will consider your research authorized, we will not pursue or support legal action against you, and we will not report you to law enforcement. If a third party takes legal action against you for research that followed this policy, we will make it known that your actions were authorized by us. If you are unsure whether something is allowed, ask us first.
Please don't
- access, modify, delete or keep data that isn't yours beyond the minimum needed to show the issue;
- degrade or disrupt our services, including through high-volume automated scanning;
- phish, social-engineer or otherwise target our team or our clients;
- attempt physical access to our offices or equipment; or
- publicly disclose the issue before we have fixed it, or before [90] days have passed since your report, whichever comes first, unless we agree otherwise.
What to expect from us
- We will acknowledge your report within [3] business days.
- We will share our initial assessment within [10] business days and keep you updated as we work.
- We will tell you when the issue is fixed.
- With your permission, we will publicly thank you for your report.
We don't currently offer a paid bug bounty.