Security

How we test, how we build, and how to report a vulnerability to us.

Our philosophy

Ethical, authorised and careful

Security testing should make systems safer without putting them, or the people who use them, at risk.

We test only with explicit written authorisation from the system owner, within an agreed scope and time window. We never test third-party systems without their owner's permission, and we don't use destructive techniques.

Our rules of engagement

  • Signed authorisation and scope before any test
  • Agreed testing windows and emergency contacts
  • No denial-of-service or destructive payloads
  • Findings stored encrypted and shared only with you
  • Secure deletion of test data after the engagement
What we assess

OWASP-aligned security testing

Our methodology follows the OWASP Top 10, the OWASP Application Security Verification Standard (ASVS) and the OWASP Web Security Testing Guide.

Vulnerability assessment

Identifying weaknesses in your application, configuration and dependencies, then confirming them manually.

Authentication testing

Login, password reset, multi-factor and OTP flows, and account enumeration.

Authorisation testing

Access control, IDOR/BOLA, and horizontal and vertical privilege escalation.

Session testing

Session expiry, logout, fixation, and cookie attributes such as Secure, HttpOnly and SameSite.

Input validation

Cross-site scripting, injection, path traversal and server-side request forgery, using non-destructive payloads.

API testing

Authentication, authorisation, rate limiting, CORS, HTTP methods, error handling and data exposure.

Secure development

How we build securely

  • No secrets in source code, front-end bundles or repositories
  • Input validation and output encoding
  • Parameterised queries and least-privilege access
  • Dependency scanning before every release
  • Safe error messages that don't leak internal details
This website

Security controls on inclusafetech.com

  • HTTPS only, with HTTP Strict Transport Security
  • A strict Content Security Policy that blocks inline and third-party scripts
  • Clickjacking protection, MIME-sniffing protection and a strict referrer policy
  • No cookies, trackers or third-party scripts
  • Spam protection on all forms
Responsible disclosure

Found a vulnerability on our website?

We welcome reports from security researchers. Report it privately, give us time to fix it, and we'll credit you in our Hall of Fame. We won't take legal action against researchers who follow our disclosure rules.