Security

Coordinated vulnerability disclosure

If you have found a vulnerability on sekuritet.com or in our services, we would very much like to hear from you. We take every report seriously and respond quickly — anything else would be odd for a security firm.

How to report

Write to security@sekuritet.com with a description of the finding: the affected URL or service, steps to reproduce, and your assessment of the potential impact. If it is urgent, call +45 70 60 56 54.

We confirm receipt as soon as possible — typically within 48 hours on business days — and keep you informed until the finding is resolved.

Our promise to you (safe harbor)

If you report a finding in good faith and within the rules on this page, we consider your research lawful and welcome: we will not report you or pursue claims against you. We are happy to credit you publicly for the finding if you wish — and fully respect it if you prefer to stay anonymous.

Ground rules

  • Give us reasonable time to fix the finding before discussing it publicly
  • Do not access, modify or delete data beyond the minimum needed to demonstrate the finding
  • Avoid actions that could disrupt operations

Scope

In scope: sekuritet.com with its subdomains and APIs.

Out of scope: denial-of-service, spam, social engineering of employees or clients, physical attempts — and vulnerabilities in third-party platforms (e.g. the underlying cloud infrastructure), which should be reported to the vendor.