Responsible Disclosure
How to report a security vulnerability in the SecAI Solutions website.
Last updated:
Review before launch. Confirm the reporting mailbox, response commitments and legal safe-harbour wording with your adviser. A security consultancy is held to its own published standard, so only commit to timelines you will meet.
We take the security of this website seriously and welcome reports from the security community.
How to report
Email [Add security contact email, e.g. security@secaisolutions.com] with:
- A description of the issue and its potential impact
- Clear steps to reproduce, including any required accounts or payloads
- Any supporting evidence — request/response pairs, screenshots, proof-of-concept
- How you would like to be credited, if at all
A machine-readable version of this policy is published at /.well-known/security.txt.
What we commit to
- Acknowledgement within
[Add timeframe, e.g. 3 business days] - An initial assessment within
[Add timeframe, e.g. 10 business days] - Regular updates while we investigate and remediate
- Public credit where you want it, once the issue is resolved
Scope
In scope: the website at secaisolutions.com and its subdomains, and the contact form endpoint.
Out of scope:
- Denial-of-service, volumetric or stress testing of any kind
- Social engineering of our team, clients or service providers
- Physical attacks against any premises
- Findings from automated scanners without a demonstrated impact
- Reports about missing headers or configuration hardening with no exploitable consequence
- Third-party services we do not operate
- Any testing that accesses, modifies or destroys data belonging to others
Safe harbour
If you make a good-faith effort to comply with this policy, we will not pursue legal action in relation to your research. Please act in good faith: stay within scope, avoid privacy violations and service degradation, use only your own test data, and give us reasonable time to remediate before any public disclosure.
[Confirm this wording with your legal adviser.]
Please do not
- Access, modify or exfiltrate data that is not yours
- Run destructive tests or attempt to degrade availability
- Publish details of an unresolved issue
Last updated: 14 August 2026