Start a project Sign in
Security

Responsible disclosure.

If you have found a weakness in our platform, we want to hear about it before anyone else does. Here is exactly how that works.

01

How to report

Emailcontact@specicon.comPGPfingerprint on requestAcknowledgementwithin 1 business dayFirst assessmentwithin 5 business days
02

In scope

●api.specicon.com and the decision API surface.●The customer console and its authentication flows.●specicon.com and its subdomains.●Our published SDKs and integration packages.
03

Out of scope

●Denial of service, volumetric or resource-exhaustion testing.●Social engineering of our staff, customers or vendors.●Reports generated only by automated scanners with no demonstrated impact.●Findings in third-party services listed as sub-processors — report those to the vendor.
04

What we commit to

●We acknowledge, investigate and tell you what we found — including when we disagree.●We fix critical issues within 7 days, high within 30, and tell you when the fix ships.●We credit you publicly if you want the credit, and stay quiet if you do not.●We will not pursue legal action for good-faith research that follows this policy.
05

Safe harbour

Research that stays within scope, avoids data destruction and privacy violations, and gives us reasonable time to fix, is authorised activity. Stop and contact us the moment you access data that is not yours.

Talk to us Back to Trust & Security