← Vulny

Vulnerability Disclosure Policy

Last updated: July 2026. Security is our business, so we welcome reports of vulnerabilities in our own systems. This policy explains how to report an issue to Vulny SIA responsibly and what you can expect in return. It follows the spirit of ISO/IEC 29147 (vulnerability disclosure) and RFC 9116 (security.txt).

1. How to report

Email support@vulny.app with a clear description of the issue, the affected URL or component, and steps to reproduce. A proof of concept, logs or screenshots help us triage faster. Please report in English where possible.

2. Our commitment to you

3. Scope

In scope: the vulny.app web application and API, our public marketing pages, and our authentication and billing flows. Out of scope: third-party services we rely on (such as Stripe or our hosting provider — report those to the respective vendor), findings that require physical access, social engineering of our staff, and volumetric denial-of-service testing.

4. Rules and safe harbour

When testing our own systems, please:

Research conducted in good faith and in accordance with these rules is authorised, and we will treat it as such — we will not pursue or support legal action, including under computer-misuse laws, in connection with it. This authorisation applies only to Vulny's own systems. It does not permit you to test any customer's assets, and nothing here overrides the authorisation requirements in our Terms and Acceptable Use Policy.

5. Rewards

We do not currently run a paid bug-bounty programme. We recognise valid reports with our thanks and, where you wish, public credit.

6. Contact and machine-readable policy

Security contact: support@vulny.app. Our machine-readable contact details are published at /.well-known/security.txt. Vulny SIA, registration number 40203753831, Kazaru street 4-59, Saurieši, LV-2118, Latvia.