Vulnerability disclosure policy
One address, a published scope, response times a small team can hold, and safe harbour for research that stays inside them.
Version 1.0.0 Effective 2026-08-24 Last updated 2026-08-24
In short
Applies to: Security researchers and their coordinators
- Report to one named address and get an acknowledgement in three business days.
- The scope names what is in and what is out, so nobody wastes a weekend.
- Safe harbour applies to research that stays inside the scope.
How to report
Send it to the address below. Include what you found, how to reproduce it, and what you think the impact is. Encrypt it if you want to and say so, and we will reply with a key.
security@tingvar.com
This address is read by the person who builds the system. It is not a shared inbox and it is not the support queue.
What is in scope
- The tingvar.com website and everything it serves
- The application and its programming interface, once they exist
- Our own account and authentication handling
What is out of scope
This list exists so nobody spends a weekend on something we are going to close. If you think a finding in this list has a real consequence here, send it anyway and say why.
- Findings against our vendors' own systems. Report those to the vendor
- Volumetric denial of service, load generation and stress testing
- Reports produced only by an automated scanner with no working example
- Social engineering of anyone who works here, and physical access attempts
- Missing hardening headers with no exploitable consequence
What happens next, and when
These are the times one person can hold. They are shorter than nothing and longer than the numbers a large security organisation publishes, and we would rather meet ours than copy theirs.
| Stage | Target |
|---|---|
| Acknowledgement that a human has read it | 3 business days |
| Triage, with our assessment of severity | 10 business days |
| Progress update, and again every 20 business days until it closes | 20 business days |
| Coordinated publication, if you want one | Agreed with you |
Safe harbour
- We will not pursue or support legal action over research that stays inside this policy.
- Stop at proof. Do not read, change or destroy data that is not yours.
- Use a test account where one is available, and tell us if you cannot.
- Give us the report before you give it to anybody else.
Research that stays inside this policy is authorised, and we will say so in writing to a third party if one asks. Research that leaves it is not, and the boundary is the scope above rather than our opinion afterwards.
Rewards
Machine readable
The same contact and expiry, and a pointer back to this scope, are published at /.well-known/security.txt, which is where a scanner looks first.