VCurl

Security disclosure

Where to report security issues with VCurl, what to expect, and what's out of scope. For how we operate the service securely day-to-day, see our trust & security FAQ.

How to report

Email team@anymosolutions.uk with a clear description of the issue, steps to reproduce, and any proof-of-concept payloads. Encrypted email is welcome; request our PGP key on first contact if you need one. Please don't share details publicly until we've had a reasonable opportunity to fix the issue.

What we ask

What you can expect

We don't currently run a paid bug bounty. We do thank researchers publicly, on request, once the issue is resolved.

In scope

Out of scope

Safe harbour

We won't pursue legal action against researchers who act in good faith, follow this policy, and report findings to us promptly. If you're unsure whether an action is permitted, ask first. We'd rather have the conversation than the surprise.

The machine-readable version of this policy is at /.well-known/security.txt per RFC 9116.