Report a vulnerability

Found a security issue on our website? Tell us responsibly, and we'll fix it and credit you in our Hall of Fame.

Responsible disclosure

Rules for testing

We appreciate the work of security researchers. If you follow these rules, we won't take legal action against you for your research, and we'll credit you in our Hall of Fame once the issue is fixed.

In scope

  • inclusafetech.com and www.inclusafetech.com
  • Cross-site scripting, injection and access control flaws
  • Authentication and session management issues
  • Sensitive data exposure
  • Security misconfigurations with a demonstrable impact

Out of scope

  • Denial-of-service, load or brute-force testing
  • Social engineering, phishing or physical attacks
  • Third-party services, including Netlify's own infrastructure
  • Reports from automated scanners without proof of impact
  • Missing headers or best practices without a demonstrable exploit
  • Clickjacking on pages with no sensitive actions
  • Spam or abuse of our contact forms

Please do

  • Test only against your own accounts and data
  • Stop as soon as you confirm a vulnerability
  • Give us reasonable time to fix the issue before any disclosure
  • Delete any data you accessed when you're done

Please don't

  • Access, change or delete other people's data
  • Disrupt our services or degrade performance
  • Use the contact forms to send malicious content
  • Share the vulnerability publicly before we've fixed it

Inclusafe doesn't currently offer monetary rewards. We thank researchers with public recognition in our Hall of Fame.

Submit a report

Fields marked with an asterisk are required. Please describe one vulnerability per report.

About you
Enter your name or researcher handle.
Enter an email address so we can follow up.
Would you like to be listed in our Hall of Fame?
Choose whether you'd like to be listed.

Leave blank to use your name or handle.

For example, LinkedIn, GitHub or HackerOne.

Enter a full web address starting with https://
The vulnerability
Choose the type of issue.
Choose a severity, or "Not sure".
Enter the full URL where you found the issue.

Numbered steps, requests and payloads that let us reproduce the issue. Don't include other people's personal data.

5000 characters left

Describe the issue in at least 30 characters.

What could an attacker do with this?

Describe the impact in at least 10 characters.
Confirm you followed the disclosure rules.

We'll acknowledge your report within 3 working days.