← Trust Center

Responsible Disclosure Policy

How to report security vulnerabilities to Optivance safely and in good faith.

Last updated: 30 June 2026

We value the work of security researchers and welcome reports that help us keep our customers safe.

Reporting

If you believe you have found a security vulnerability, email security@optivance.co.uk with enough detail to reproduce the issue. For sensitive reports, you may encrypt your message using our PGP key, available at [PGP key URL].

Our commitment to you

If you make a good-faith effort to comply with this policy during your research, we will:

  • Acknowledge your report within three business days.
  • Work with you to understand and resolve the issue.
  • Not pursue or support legal action against you for good-faith research.

Guidelines (safe harbour)

Please:

  • Only test against your own account or accounts you have explicit permission to test.
  • Avoid privacy violations, data destruction, and service disruption — no denial-of-service, spam, or social engineering.
  • Do not access, modify, or exfiltrate data that is not yours.
  • Give us reasonable time to remediate before any public disclosure.

Out of scope

Typically out of scope: reports of missing best-practice headers without demonstrable impact, rate-limiting on non-sensitive endpoints, and output from automated scanners without proof of exploitability.

Recognition

With your permission, we are happy to credit researchers who report valid issues. We do not currently operate a paid bug bounty.

Questions about this? Contact our security & privacy team.

Contact us