Vulnerability disclosure policy.
We spend our days reporting vulnerabilities to other teams. If you have found one in ours, we want to know, and we will treat you the way we ask to be treated.
Effective July 2026
scope
In scope: causalsecurity.com and subdomains we operate.
Out of scope: third-party services we use (Cloudflare, Plausible, Google's booking page), denial-of-service and volumetric testing, social engineering, and physical attacks.
how to report
Email security at this domain. Tell us what you found, where, how to reproduce it, and your read on the impact. Automated tools are a fine way to look; just validate what they flag before sending it, and include a short proof of concept where you can.
While you research: use your own accounts and data where possible, do not access or change data that is not yours, and pause and report once you have shown the issue is real. That is all we ask.
what to expect
We acknowledge reports within 3 business days. We keep you informed while we investigate, fix validated issues promptly, and coordinate with you on timing before anything is public.
Reports like yours make our own work better, and we are genuinely grateful for the time behind them. We cannot offer monetary bounties right now. What we promise is a careful, prompt response from people who do this work themselves, and our sincere thanks.
safe harbor
Good-faith research consistent with this policy is authorized. We will not pursue or support legal action against you for it, and if a third party raises your research with us, we will confirm it was authorized under this policy.