Security policy
Effective 27 September 2026 · version 2026-09-27
1. Reporting a vulnerability
E-mail security@certascent.com with what you found, the steps to reproduce it and the impact you expect. Encrypt nothing you would not want us to read; please don't include other people's personal data. Our security contact is also published in /.well-known/security.txt.
2. Scope
In scope: the public website certascent.com, the web app and API at app.certascent.com, and the CertAscent source code. Out of scope: our providers' own services (Cloudflare, Fly.io, Neon, Postmark, Anthropic; report to them directly), denial-of-service and volume testing, social engineering of people, physical attacks, spam or mass account creation, and findings that need a compromised device or browser.
3. What we ask
Test only with accounts you own (CertAscent is in a private, invite-only beta: ask security@certascent.com for a test account if you need one), stop as soon as you can show the issue, never access, change or keep other people's data, and give us reasonable time to fix the issue before you share details publicly.
4. What you can expect
We acknowledge reports within 3 business days, give you an assessment within 10 business days and keep you updated until the issue is fixed. We credit reporters who want to be credited. There is no paid bug bounty during the beta.
5. Good-faith research
If you follow this policy, we will treat your research as authorised, work with you to understand and fix the issue, and will not pursue or support legal action against you for it. If in doubt about whether something is allowed, ask us first at security@certascent.com.
See also the Privacy Notice and the Disclaimer & terms of use.