Security disclosure
How to report
Email team@anymosolutions.uk with a clear description of the issue, steps to reproduce, and any proof-of-concept payloads. Encrypted email is welcome; request our PGP key on first contact if you need one. Please don't share details publicly until we've had a reasonable opportunity to fix the issue.
What we ask
- Test only against accounts you own. Don't access, modify, or download data belonging to other users.
- Don't run automated scans that materially degrade the service for other users.
- Don't attempt social engineering, phishing, or physical attacks against staff or infrastructure.
- Give us a reasonable time to investigate and patch before publishing.
What you can expect
- An acknowledgement within 3 business days.
- A triage decision (in scope, out of scope, duplicate, etc.) within 10 business days.
- An update on remediation progress as the fix lands.
- Public credit on a researchers page if you'd like it, once the fix is shipped.
We don't currently run a paid bug bounty. We do thank researchers publicly, on request, once the issue is resolved.
In scope
- VCurl application code and the surfaces it exposes (web, API, panels).
- Authentication, authorisation, session management, MFA, OAuth.
- Data isolation between tenants.
- Personal-data handling, GDPR-relevant features.
Out of scope
- Denial-of-service, brute-force, or rate-limit testing without prior written agreement.
- Vulnerabilities in third-party services we depend on. Report those directly to the vendor.
- Missing security headers / SPF / DMARC / DKIM hardening reports without a demonstrated impact.
- Self-XSS, clickjacking on pages without sensitive actions, and similar low-impact findings.
- Outdated browser support claims (we follow current LTS / evergreen browser baselines).
Safe harbour
We won't pursue legal action against researchers who act in good faith, follow this policy, and report findings to us promptly. If you're unsure whether an action is permitted, ask first. We'd rather have the conversation than the surprise.
The machine-readable version of this policy is at
/.well-known/security.txt
per RFC 9116.