Coordinated vulnerability disclosure
If you have found a vulnerability on sekuritet.com or in our services, we would very much like to hear from you. We take every report seriously and respond quickly — anything else would be odd for a security firm.
How to report
Write to security@sekuritet.com with a description of the finding: the affected URL or service, steps to reproduce, and your assessment of the potential impact. If it is urgent, call +45 70 60 56 54.
We confirm receipt as soon as possible — typically within 48 hours on business days — and keep you informed until the finding is resolved.
Our promise to you (safe harbor)
If you report a finding in good faith and within the rules on this page, we consider your research lawful and welcome: we will not report you or pursue claims against you. We are happy to credit you publicly for the finding if you wish — and fully respect it if you prefer to stay anonymous.
Ground rules
- Give us reasonable time to fix the finding before discussing it publicly
- Do not access, modify or delete data beyond the minimum needed to demonstrate the finding
- Avoid actions that could disrupt operations
Scope
In scope: sekuritet.com with its subdomains and APIs.
Out of scope: denial-of-service, spam, social engineering of employees or clients, physical attempts — and vulnerabilities in third-party platforms (e.g. the underlying cloud infrastructure), which should be reported to the vendor.