Security

Security & Responsible Disclosure Policy

How to report suspected security vulnerabilities safely

Certifiedge Internally Approved — Deployment Activation PendingPublic activation is intentionally blocked until verified operator/provider details are configured.

Report route

Reports should include the affected component, reproduction steps, impact and evidence needed to investigate without collecting unnecessary personal data.

Good faith

Good-faith research that avoids harm, persistence, destructive actions, social engineering, privacy invasion and unnecessary data access is distinguished from abuse.

Do not

Do not exfiltrate data, access unrelated accounts, create persistence, degrade service or publicly disclose an unresolved issue in a way that increases harm.

Response

Certifiedge records the report, triages severity, coordinates remediation and communicates status where appropriate. This policy is not a bug-bounty promise unless a bounty programme is separately announced.

Questions or requests

Use the Certifiedge contact, complaints or data-rights route appropriate to the issue. Internal policies do not remove rights or remedies available under applicable law.