Diagnostic

Vulnerability Disclosure

A security concern needs a safe route to the right person.

How to report a potential vulnerability.

3 min read

SI welcomes responsible reports concerning potential vulnerabilities affecting systems explicitly listed within the approved scope.

Good-faith reporting

Reporters should comply with applicable law, avoid privacy violations, use the minimum testing reasonably required, stop if sensitive information is encountered, avoid persistence, provide reproducible detail and allow reasonable time for assessment.

Do not engage in denial-of-service testing, social engineering, password spraying, destructive testing, employee targeting, unauthorised access to third-party systems or unnecessary data access.

Report contents

  • Affected system
  • Clear description
  • Reproduction steps
  • Likely impact
  • Date and time
  • Supporting evidence
  • Contact details
  • Proposed disclosure timing where applicable

Response boundary

SI uses only operationally supportable commitments. It does not promise a bounty, fixed resolution period, public acknowledgement, immunity or a particular severity classification unless formally approved.

Security email: [MONITORED SECURITY EMAIL]

security.txt

SI deploys an approved /.well-known/security.txt with current Contact, Expires, Policy, Preferred-Languages and Canonical values. The mailbox is monitored and the expiry maintained.

Search Intelligence Review Data Security and Confidentiality Contact Search Intelligence

Report the concern without creating a second one.