Vulnerability Disclosure Policy

Found something?
Tell us first.

We welcome reports from security researchers. This policy explains how to report a vulnerability to Fyltre and what you can expect from us in return.

Last updated — June 2026

Fyltre Ltd (“Fyltre,” “we,” “our,” or “us”) takes the security of our service seriously. We value the work of the security community and welcome the responsible disclosure of vulnerabilities. This policy sets out how to report an issue and the commitments we make to researchers who act in good faith.

01

How to report

If you believe you have found a security vulnerability in Fyltre, please report it to us privately via our contact channel before disclosing it publicly. Where possible, please include:

  • A clear description of the vulnerability and its potential impact
  • Step-by-step instructions to reproduce the issue
  • Any proof-of-concept code, screenshots, or logs that help us understand it
  • Your contact details so we can follow up
02

Our commitment to you

  • We aim to acknowledge your report within one business day.
  • We will investigate and keep you informed of our progress as we work toward a fix.
  • We will not pursue or support legal action against researchers who act in good faith and comply with this policy.
  • With your permission, we are happy to credit you once the issue is resolved.
03

Guidelines for researchers

When testing, we ask that you:

  • Make every effort to avoid privacy violations, data loss, and service disruption
  • Only interact with accounts you own or have explicit permission to test
  • Do not access, modify, or delete data that does not belong to you
  • Do not run automated scans that degrade or disrupt the service
  • Give us a reasonable opportunity to remediate before any public disclosure
04

In scope

  • The Fyltre web application and its API
  • Authentication, authorisation, and access control issues
  • Data exposure, injection, and similar application-level vulnerabilities
05

Out of scope

  • Vulnerabilities in third-party services we rely on (report those to the provider directly)
  • Social engineering, phishing, or physical attacks against Fyltre staff or facilities
  • Denial-of-service attacks or volumetric testing
  • Reports from automated tools without demonstrable, exploitable impact
06

Handling of reports

Confirmed vulnerabilities are triaged and remediated under our Incident Response Policy. We prioritise fixes according to severity and the risk posed to customer data.

07

Contact

To report a vulnerability or ask about this policy:
Fyltre Ltd get in touch