Vulnerability Disclosure
If you find a security vulnerability in our website or systems, we would rather hear it from you than from someone else.
Last updated: 1 August 2026
1. How to report
Email info@smarttechctc.io with a subject line starting with [SECURITY]. Where you can, please include:
- The affected URL or component.
- Steps to reproduce.
- The practical impact as you assess it.
- How we can reach you.
2. What we commit to
- Acknowledge your report within 3 business days.
- Share our assessment and remediation plan within 14 business days.
- Take no legal action against good-faith researchers who follow section 3.
- Credit your contribution if you are happy to be named.
We do not currently run a paid bug bounty programme.
3. Testing we accept
When testing, please:
- Only affect your own accounts and data.
- Stop as soon as you have demonstrated the vulnerability — do not exploit further.
- Do not download, modify or delete anyone else's data.
- Do not run denial-of-service attacks, send spam, or attempt social engineering against our staff.
- Give us time to fix the issue before publishing it.
4. Out of scope
- Reports produced solely by automated scanners with no demonstrated impact.
- Configuration observations that carry no concrete risk.
- Issues in third-party systems we do not operate.