Security & Vulnerability Disclosure

Effective: April 29, 2026

We welcome reports from independent security researchers. This page is the policy referenced from /.well-known/security.txt and is incorporated into our DPA Annex II as part of our incident-response programme.

Reporting a vulnerability

Email security@axolotlarmy.net with a clear description, reproduction steps, and (if possible) a proof of concept. Please do not include real user data; if a finding requires authenticated access, request a test account first.

For findings that contain customer data we ask that you encrypt the report. Public PGP key fingerprint: provided on request to security@axolotlarmy.net.

Scope

Out of scope

Safe harbour

We will not pursue legal action against researchers who act in good faith, do not access user data beyond what is necessary to demonstrate the vulnerability, do not degrade the Service, do not pivot to other customers' tenants, and give us a reasonable time to remediate before public disclosure. Researchers who follow this policy are authorised to access the Service for the limited purpose of testing.

Response targets

Coordinated disclosure

We ask researchers to give us 90 days from triage before public disclosure, or 30 days for criticals where customers are exposed. We are happy to coordinate joint advisories, CVE assignment via MITRE, and credit in the Hall of Fame below.

Hall of fame

With your permission we will credit you here after the issue is resolved. We do not currently run a paid bounty programme; we may send swag, write a public thank-you, or both.

What we do internally

SOC 2

We are working toward SOC 2 Type II readiness with a target attestation in 2027. Enterprise customers can request an Attestation of Compliance (AoC) snapshot under NDA before the formal report is published.

Contact

Security: security@axolotlarmy.net