Security Vulnerability Disclosure Policy
Reporting a security vulnerability
If you believe you have found a security vulnerability in a Simpleum product, website, or public service, please report it confidentially to security@simpleum.com.
Please include enough information for us to understand and reproduce the issue, such as the affected product or service, version or URL, steps to reproduce, potential impact, and a proof of concept if available.
Coordinated disclosure
Please do not publicly disclose the vulnerability before we have had a reasonable opportunity to investigate and address it. We will handle reports in good faith and coordinate disclosure with you where appropriate.
Scope and contact boundaries
This policy covers SimpleumSafe, SimpleumCheck, the Simpleum website, and publicly operated Simpleum services. This address is only for security vulnerabilities. For product support, please use our support contact. For privacy requests, please use the contact details in our privacy policy.