Vulnerability Disclosure
We welcome good-faith security research and appreciate reports that help keep SEDER ONE and its users safe.
How to report
Email security@sederone.com with a description of the issue and its impact, steps to reproduce (a proof-of-concept helps), and the affected URL, endpoint, or version.
What to expect
We acknowledge valid reports and work to remediate them. We do not operate a paid bug-bounty program at this time. Please give us a reasonable opportunity to fix an issue before any public disclosure.
Scope
In scope: the SEDER ONE application and its official sederone.com domains. Out of scope: social engineering, physical attacks, denial-of-service, spam, and findings that require a compromised device or an account you don't own.
Safe harbor
Good-faith research that respects user privacy, stays within scope, and avoids service disruption or data destruction will not be pursued legally. Do not access, modify, or retain data that isn't yours; if you encounter personal data, stop and report it.
This policy is also published at /.well-known/security.txt.