Effective 14 July 2026

Security Policy

Reporting

Report vulnerabilities privately to [email protected]. We target acknowledgement within three business days, critical fixes within seven days, and other validated fixes within thirty days.

Safe harbour

Good-faith research is welcome when it avoids privacy violations, persistence, destructive actions, social engineering, and disruption. Stop after minimum proof and allow reasonable remediation time before publication.

Scope

In scope: certkit.logicues.com, verification pages, and the public API. Customer SMTP servers and volumetric denial-of-service testing are out of scope. There is no cash bounty.