Effective 14 July 2026
Security Policy
Reporting
Report vulnerabilities privately to [email protected]. We target acknowledgement within three business days, critical fixes within seven days, and other validated fixes within thirty days.
Safe harbour
Good-faith research is welcome when it avoids privacy violations, persistence, destructive actions, social engineering, and disruption. Stop after minimum proof and allow reasonable remediation time before publication.
Scope
In scope: certkit.logicues.com, verification pages, and the public API. Customer SMTP servers and volumetric denial-of-service testing are out of scope. There is no cash bounty.