← Trust Center
Policy

Vulnerability Disclosure Policy

How to report a security vulnerability in any SafeToOpen product, website or service — and what we commit to in return.

Classification: Public · Version: 1.0 — July 2026 · URL: safetoopen.com/en/security/ (linked from the Trust Center)

SafeToOpen welcomes reports from security researchers and the public. If you believe you have found a security vulnerability in any SafeToOpen product, website, or service, we want to hear from you.

How to report

Email [email protected] with: a description of the issue and where it was found, steps to reproduce (proof-of-concept welcome), and your contact details for follow-up.

What we promise

We will acknowledge your report within 3 business days, keep you informed of progress, and tell you when the issue is fixed. We aim to remediate confirmed vulnerabilities within our published severity targets: critical 48 hours, high 7 days, medium 30 days, low 90 days. With your permission, we will credit you in our release notes. We will not pursue legal action against researchers who follow this policy in good faith.

Scope and rules

In scope: the SafeToOpen browser extensions, APIs, cloud services, and safetoopen.com.

Out of scope: denial-of-service testing, social engineering of SafeToOpen staff or customers, physical attacks, spam, and issues in third-party services we use (please report those to the third party).

Good-faith rules: do not access, modify, or delete data that isn't yours; stop and report immediately if you encounter personal data; do not degrade the service for others; give us 90 days to remediate before public disclosure.

We do not currently operate a paid bug bounty program; we gratefully credit researchers who help keep SafeToOpen users safe.

security.txt (deploy at https://safetoopen.com/.well-known/security.txt)

`

Contact: mailto:[email protected]

Expires: 2027-07-31T23:59:00.000Z

Preferred-Languages: en

Canonical: https://safetoopen.com/.well-known/security.txt

Policy: https://safetoopen.com/en/security/

`

Operational note: the Expires field is required by RFC 9116 and must be refreshed before July 2027 — it is on the annual trust-center calendar (Blueprint Phase 4).

Questions from your security team?

We answer reviewer questions directly and provide the full security review pack under NDA — typical turnaround one business day.

Contact [email protected]