Vulnerability Disclosure Policy
1. A Safe Route to the Right Person
Search Intelligence welcomes responsible reports concerning potential vulnerabilities affecting systems explicitly listed within the approved scope.
2. Good-Faith Reporting
Reporters should comply with applicable law, avoid privacy violations, use the minimum testing reasonably required, stop if sensitive information is encountered, avoid persistence, provide reproducible detail and allow reasonable time for assessment.
Do not engage in denial-of-service testing, social engineering, password spraying, destructive testing, employee targeting, unauthorised access to third-party systems or unnecessary data access.
3. Report Contents
- Affected system
- Clear description
- Reproduction steps
- Likely impact
- Date and time
- Supporting evidence
- Contact details
- Proposed disclosure timing, where applicable
4. Response Boundary
We use only operationally supportable commitments. We do not promise a bounty, fixed resolution period, public acknowledgement, immunity or a particular severity classification unless formally approved.
5. Reporting Route
Security email: diane@seolens.co.za
6. security.txt
We maintain an approved /.well-known/security.txt file with current Contact, Expires, Policy, Preferred-Languages and Canonical values. The mailbox is monitored and the expiry maintained.