Vulnerability Disclosure

If you find a security vulnerability in our website or systems, we would rather hear it from you than from someone else.

Last updated: 1 August 2026

1. How to report

Email info@smarttechctc.io with a subject line starting with [SECURITY]. Where you can, please include:

  • The affected URL or component.
  • Steps to reproduce.
  • The practical impact as you assess it.
  • How we can reach you.

2. What we commit to

  • Acknowledge your report within 3 business days.
  • Share our assessment and remediation plan within 14 business days.
  • Take no legal action against good-faith researchers who follow section 3.
  • Credit your contribution if you are happy to be named.

We do not currently run a paid bug bounty programme.

3. Testing we accept

When testing, please:

  • Only affect your own accounts and data.
  • Stop as soon as you have demonstrated the vulnerability — do not exploit further.
  • Do not download, modify or delete anyone else's data.
  • Do not run denial-of-service attacks, send spam, or attempt social engineering against our staff.
  • Give us time to fix the issue before publishing it.

4. Out of scope

  • Reports produced solely by automated scanners with no demonstrated impact.
  • Configuration observations that carry no concrete risk.
  • Issues in third-party systems we do not operate.