Security
Security
How to responsibly report a security vulnerability in Contellect One or our website: our disclosure policy, scope, safe harbor, researcher guidelines, and coordinated-disclosure commitments.
Contellect Technologies Inc. (“Contellect”) takes the security of Contellect One and our websites seriously. We welcome reports from security researchers, customers, and members of the public who identify potential vulnerabilities, and we are committed to working with you to verify, reproduce, and remediate valid issues quickly.
This policy explains how to report a vulnerability, what is in and out of scope, the protections we offer good-faith researchers, and what you can expect from us in return.
Reporting a Vulnerability
If you believe you have found a security vulnerability in a Contellect system, please email us at security@contellect.com.
Please do not report security issues through public channels such as GitHub issues, social media, support tickets, or our general contact form. Reporting privately gives us the opportunity to fix the issue before it can be exploited.
What to include in your report
To help us verify and address the issue quickly, please include as much of the following as you can:
- A clear description of the vulnerability and its type (for example: authentication bypass, injection, cross-site scripting, insecure access control, or information disclosure).
- The affected asset: the exact URL, endpoint, or component, and the environment or version where you observed it.
- Step-by-step reproduction instructions, detailed enough for our team to reproduce the issue independently. Include HTTP requests/responses or
curlcommands where relevant. - A proof of concept: a minimal script, request, screenshot, or short video that demonstrates the issue. Please redact any real personal data.
- Impact: what an attacker could achieve, and which data or users could be affected.
- Optional but helpful: a severity self-assessment (for example a CVSS v3.1 vector) and any suggested remediation.
Reports written in English are preferred.
Scope
In scope
- The Contellect One platform and its APIs.
- Contellect websites, including contellect.com and its subdomains.
- Cloud infrastructure and services that Contellect owns and operates.
Out of scope
The following are generally out of scope and not eligible for recognition. Please do not test for or submit these unless you can demonstrate a concrete, exploitable security impact:
- Denial-of-service (DoS/DDoS), volumetric, brute-force, or rate-limiting tests, and any activity that degrades or interrupts our services.
- Findings from automated scanners without a manually verified, exploitable impact.
- Missing security headers, cookie flags, or other “best-practice” hardening with no demonstrated impact.
- Reports of outdated software versions or banner/version disclosure without a working exploit.
- Self-XSS, clickjacking on pages with no sensitive action, or issues requiring an unlikely amount of user interaction.
- Vulnerabilities in third-party services, libraries, or integrations that we do not control; please report those to the responsible vendor.
- Social engineering, phishing, or physical attacks against Contellect staff, customers, or facilities.
- Spam, content, SEO, or purely cosmetic issues.
- Issues that affect only unsupported browsers, or only your own account with no cross-user impact.
If you are unsure whether something is in scope, email us first and ask.
Safe Harbor
We support responsible, good-faith security research and want you to feel safe reporting to us. If you make a good-faith effort to comply with this policy during your research, Contellect will:
- Consider your research to be authorized under applicable computer-misuse and anti-hacking laws, and we will not pursue or support legal action against you for accidental, good-faith violations of this policy.
- Work with you to understand and resolve the issue quickly, and recognise your contribution if you wish.
This safe harbor applies only to legal claims within Contellect’s control. It does not bind third parties, and it does not authorise activity that is unlawful or that violates the rights of others. If you are unsure whether a specific action is permitted, ask us before proceeding. This policy follows the principles of the disclose.io safe-harbor framework.
Researcher Guidelines
To stay within this policy and qualify for safe harbor, please:
- Do limit your testing to in-scope systems.
- Do stop and report as soon as you discover a vulnerability, and access only the minimum data necessary to demonstrate it.
- Do give us a reasonable opportunity to remediate before disclosing publicly.
- Do keep the details of the vulnerability confidential until we have resolved it and agreed on disclosure with you.
Please also:
- Do not access, modify, delete, store, or exfiltrate data that is not your own. If you encounter personal or confidential data, stop immediately, do not save it, and tell us.
- Do not degrade, disrupt, or overload our services, or attempt any form of denial-of-service.
- Do not use social engineering, phishing, or physical intrusion.
- Do not publicly disclose the issue, or share it with third parties, before a fix is in place and we have coordinated disclosure with you.
- Do not demand payment in exchange for disclosing a vulnerability.
Our Response Commitments
When you report a vulnerability in line with this policy, you can expect us to:
- Acknowledge receipt of your report within 3 business days.
- Triage and validate the report (confirming whether it is valid and in scope, and assessing its severity), and share an initial assessment, typically within 10 business days.
- Keep you informed of remediation progress at reasonable intervals until the issue is resolved.
- Prioritise remediation by severity, addressing critical and high-severity issues as quickly as possible.
- Coordinate public disclosure with you. We ask that you keep findings confidential until a fix is released. We aim to resolve valid reports within 90 days, after which we will work with you on coordinated disclosure. If we need more time, we will explain why and agree a revised timeline in good faith.
Recognition
We are grateful to the researchers who help keep Contellect and our customers safe. With your permission, we are happy to publicly acknowledge your contribution once an issue is resolved. Let us know how you would like to be credited (name or alias, and an optional link), or tell us if you would prefer to remain anonymous.
Contellect does not currently operate a paid bug-bounty program.
Encrypted Reports and security.txt
Email to security@contellect.com over TLS is sufficient for most reports. If your report is especially sensitive and you would like to encrypt it, contact us and we will provide a PGP key.
A machine-readable security.txt file, following RFC 9116, is published at /.well-known/security.txt.
Standards
This disclosure policy is informed by widely recognised standards and guidance for vulnerability disclosure and handling, including ISO/IEC 29147 (vulnerability disclosure), ISO/IEC 30111 (vulnerability handling), RFC 9116 (security.txt), the disclose.io safe-harbor framework, and the OWASP vulnerability-disclosure guidance.
Contact
- Security reports: security@contellect.com
- General enquiries: contact@contellect.com (or use our contact form)
- Company: Contellect Technologies Inc.
Last updated: July 8, 2026