Responsible Disclosure Policy
How to report security vulnerabilities to Optivance safely and in good faith.
Last updated: 30 June 2026
We value the work of security researchers and welcome reports that help us keep our customers safe.
Reporting
If you believe you have found a security vulnerability, email security@optivance.co.uk with enough detail to reproduce the issue. For sensitive reports, you may encrypt your message using our PGP key, available at [PGP key URL].
Our commitment to you
If you make a good-faith effort to comply with this policy during your research, we will:
- Acknowledge your report within three business days.
- Work with you to understand and resolve the issue.
- Not pursue or support legal action against you for good-faith research.
Guidelines (safe harbour)
Please:
- Only test against your own account or accounts you have explicit permission to test.
- Avoid privacy violations, data destruction, and service disruption — no denial-of-service, spam, or social engineering.
- Do not access, modify, or exfiltrate data that is not yours.
- Give us reasonable time to remediate before any public disclosure.
Out of scope
Typically out of scope: reports of missing best-practice headers without demonstrable impact, rate-limiting on non-sensitive endpoints, and output from automated scanners without proof of exploitability.
Recognition
With your permission, we are happy to credit researchers who report valid issues. We do not currently operate a paid bug bounty.
Questions about this? Contact our security & privacy team.
Contact us