Skip to content
Security

Responsible Disclosure

We welcome reports of security vulnerabilities that affect CHAINTEGRITY systems, websites, or client infrastructure. This page describes how to report issues responsibly and what you can expect from us.

1. Scope

Reports should relate to the security of our website, infrastructure, or services. We do not authorise testing of third-party systems or systems outside the defined scope of an engagement.

2. Rules of Engagement

  • Do not access, modify, or destroy data that does not belong to you.
  • Do not disrupt services or exploit vulnerabilities beyond the minimum required to confirm them.
  • Do not share confidential details publicly until we have agreed a disclosure timeline.
  • Provide enough information for us to reproduce and assess the issue.

3. How to Report

Send reports to the contact form or the secure email address provided during an engagement. Include a clear description, steps to reproduce, impact assessment, and any proposed mitigation.

4. Our Commitments

  • We will acknowledge receipt of your report promptly.
  • We will investigate and validate the issue in a reasonable timeframe.
  • We will keep you informed of progress and coordinate public disclosure if appropriate.
  • We will not take legal action against researchers who comply with these guidelines.

5. Public Recognition

Where appropriate and with your consent, we may publicly acknowledge your contribution in a security advisory or case study.

Last updated: 19 August 2026.