Security

Responsible Disclosure Policy

The security and privacy of the data of our clients and users is important to Adnuntius. We want to hear from security researchers who have information related to suspected vulnerabilities in any Adnuntius service handling user data.

Contents
1. Scope 2. Reporting a Vulnerability 3. Your Responsibilities 4. Prohibited Conduct 5. Out of Scope 6. Safe Harbour & Legal Terms 7. Submission Form
Last updated 16/08/2025
Section 1

Scope

The security and privacy of the data of our clients and users (“User Data”) is important to Adnuntius (“We”). We take our responsibility to protect this user data seriously and use technical, administrative, and physical controls in order to safeguard it.

We want to hear from security researchers (“You” or “Your”) who have information related to suspected security vulnerabilities (“Vulnerability” or “Vulnerabilities”) of any Adnuntius services handling user data. Please report any such vulnerabilities to us in accordance with these Vulnerability Disclosure Terms (“Terms”).

Services in scope:

  • adnuntius.com
  • Any subdomains of adnuntius.com, for example docs.adnuntius.com

If you submit a vulnerability in accordance with all of the Terms, Adnuntius will work with you to understand, validate, and address the vulnerability. We may, at our discretion, provide a monetary reward for any issue we deem serious, in which case you are responsible for any tax implications of such a payment depending on your country of residency and citizenship.

Thank you for your help in making Adnuntius more secure.


Section 2

Reporting a Vulnerability

Please submit your vulnerability to Adnuntius by completing the form at the end of these terms, and submitting both the completed form and vulnerability to security@adnuntius.com (“Report”). By submitting your report to Adnuntius you agree to all of the following:

  • You agree not to publicly disclose the vulnerability until Adnuntius agrees to a public disclosure. We have the ability to fix issues immediately on receiving a report, and will disclose after ensuring all customer data is safe, but you must allow us up to 90 days to do so.
  • You agree to keep all communication with Adnuntius confidential
  • You represent that you did not copy the report or any part of it from another third party
  • You allow Adnuntius and its affiliates the ability to use, distribute, and/or disclose information provided in your report for security remediation and related purposes
Report a vulnerability

Send your completed submission form and vulnerability details to our security team.

security@adnuntius.com

Section 3

Your Responsibilities

We ask that you do all of the following in conducting your research:

  • Comply with all applicable laws
  • Only interact with your own accounts or test accounts, not with other users
  • Contact us immediately if you encounter user data. Do not access or save the data, and immediately purge it after reporting the vulnerability to Adnuntius

Section 4

Prohibited Conduct

We expressly prohibit any of the following conduct:

  • Publicly disclosing a vulnerability without our consent
  • Accessing or modifying our data or our users’ data
  • Degrading our services via Denial of Service attacks, including spamming forms
  • Attacks on third party services

Section 5

Out of Scope

The following issues are outside the scope of our vulnerability disclosure program:

  • Attacks which in our judgement could not be exploited to obtain user data
  • Attacks which cannot be used to affect another Adnuntius user, such as Self-XSS
  • Attacks requiring physical access to a user’s device
  • Any access to data where the targeted user needs to be operating a rooted mobile device
  • Any physical attempts against Adnuntius property or data centers
  • Social engineering of Adnuntius employees or contractors
  • Email security configuration issues such as SPF/DMARC/MTA-STS records
  • Password, email and account policies, such as email id verification, reset link expiration, password complexity
  • Absence of rate limiting, unless related to authentication
  • Any report that discusses how you can learn whether a given username, email address has an Adnuntius account
  • Hyperlink injection or any link injection in emails we send
  • Lack of CSRF tokens unless you can show how this is exploitable to obtain our user data
  • Attacks, such as clickjacking, which require the attacker to overlay on top of an Adnuntius webpage
  • Vulnerabilities affecting users of outdated browsers or platforms
  • Open ports on servers operated by Adnuntius, unless that port exposes a service containing user data
  • Denial of service attacks


Section 7

Adnuntius Vulnerability Submission Form

Fill this in, then copy the report or open it in your mail client. Nothing is sent to us from this page — your report reaches us only when you email it to security@adnuntius.com.

Contact Information
If any.
Vulnerability Details
What an attacker could achieve by exploiting this vulnerability.
Optional.
Researcher Declaration
Typed name.