Report a security issue
If you have found a security problem in something we run, we want to hear about it. This page is how to reach us.
How to reach us
Write to security@cmsinfosec.com. That address goes to us directly and is the same one published in our security.txt, which is the machine-readable version of this page for the tools that look for one.
English please. We would rather have a report in imperfect English than not have it, so do not let the wording stop you sending it.
What helps
A report we can act on beats a polished one. If you can, tell us what the problem is, where you found it, and enough for us to see it happen ourselves. If you think you know what an attacker could do with it, say so, because that is usually the part that decides how fast we move.
Please do not go looking inside other people's accounts or data to prove a point. If a problem can only be demonstrated that way, describe it and we will work out how to reproduce it against our own.
What we have not published yet
We have not published safe harbour terms, a scope, or a response time, and we would rather say that plainly than let this page imply protections that do not exist. Nothing here is a promise about what we will do with a report or a commitment not to act on one.
That is a gap we intend to close, and when those terms are agreed they will be published on this page. If that matters to you before you send us something, write to security@cmsinfosec.com and ask.
Reporting a scam instead
This page is for security problems in things CMS InfoSec runs. If you have been targeted by a scam and are looking for help, our products and the advice in them are the better starting point, and what we build explains which one fits.
