Security Reporting
Security Reporting
A responsible starting point for a technical security finding.
Start with the affected service
Identify the product or public page, the nature of the finding and a concise description of the observed behaviour. Include only information necessary for an initial assessment. Do not include another person’s private records, credentials or intrusive evidence in a general email.
Use Softa’s published contact directory to confirm the appropriate security channel. A later secure exchange may be appropriate for sensitive details. This page does not establish a bug-bounty award, a safe-harbour promise or a guaranteed response deadline.
Keep the purpose specific
A product-support issue, a personal-data request and a technical vulnerability are different matters. The Help and Support page distinguishes those routes. Reporting a finding does not authorise further access, disruption or collection of other people’s information.
This website does not upload a report or mark it received. The published contact is the starting point for a properly scoped exchange.
