← Back to Home

Vulnerability Disclosure Policy

Last updated: September 11, 2026

We would rather hear about a security problem from you than read about it somewhere else. If you have found something, this page tells you how to report it and what we will do in return.

How to report

Email {{SECURITY_EMAIL}} with enough detail for us to reproduce the issue — the affected URL or endpoint, the steps you took, and what you saw. A proof of concept helps. Screenshots or a short recording are welcome.

Please report in English or Norwegian. You do not need to have a fix in mind, and you do not need to be certain it is exploitable.

What we commit to

  • We will acknowledge your report within 3 working days.
  • We will tell you our assessment, including if we disagree that it is a vulnerability and why.
  • We will keep you updated while we work on it, and tell you when it is fixed.
  • We will not take legal action against you for research carried out in good faith under this policy, and we will not report you to law enforcement for it.
  • We will credit you when we announce the fix, if you would like us to. Tell us how you want to be named.

We are a small team, so we ask for patience on timelines rather than promising same-day fixes we cannot deliver. If you believe we are not taking a report seriously, say so plainly and we will escalate it.

What we ask of you

  • Give us reasonable time to fix the issue before you publish. We suggest 90 days, and we will usually be much faster.
  • Use only accounts you own, or test accounts you have created. Do not access, modify or retain other people's data.
  • If you do encounter someone else's personal data, stop, do not save a copy, and tell us what you saw in your report.
  • Do not run denial-of-service, volumetric or load tests against our production service.
  • Do not use social engineering, phishing or physical attacks against our staff or our suppliers.

In scope

  • Our website and the analysis interface
  • Our API
  • Our browser extension

Out of scope

These are things we already know about or have decided not to treat as vulnerabilities, so a report about them will be closed:

  • Findings from automated scanners with no demonstrated impact, including missing headers on pages that carry no sensitive data.
  • Missing security hardening that is not exploitable on its own, unless you can chain it into something that is.
  • Our admin login page being publicly reachable. It contains no secret; authentication is enforced server-side, with constant-time comparison and rate limiting. If you can get past it, that is very much in scope.
  • Reports that our detection results are wrong or can be evaded. AI detection is probabilistic and we say so; a way to defeat detection is a product limitation, not a security vulnerability. We are still interested to hear about it — just not under this policy.
  • Vulnerabilities in third-party detection providers. Please report those to the provider. We are happy to help you make contact.

Rewards

We do not currently run a paid bug bounty. We will not pretend otherwise to attract reports. What we offer is a fast, honest response and public credit. If you need to be paid for your time, please tell us before you invest a lot of it, so neither of us is disappointed.

Data protection reports

If your concern is about how we handle personal data rather than a technical flaw, our Privacy Policy has the right contact and explains your rights.


← Back to Home