Security Disclosure
How to responsibly report a security vulnerability in this website, and what you can expect from us when you do.
Last updated: 17 July 2026
Our commitment
Information security is what we do for our clients, and we hold our own systems to the same standard. If you have found a security weakness in this website, we want to hear about it, and we will work with you to understand and resolve it.
This policy explains what we consider in scope, how to report an issue, and the protections that apply when you report in good faith.
What is in scope
This policy covers www.conformiteassist.com, together with the enquiry form and the API endpoints that run on it.
- Vulnerabilities that could expose enquiry data submitted through the contact form.
- Vulnerabilities that could allow someone to take over, deface, or inject content into the website.
- Weaknesses in the captcha, honeypot or rate-limiting controls that protect the contact form.
What is out of scope
- Denial of service, volumetric testing, or any form of load testing.
- Spam, phishing or social engineering directed at our people, and any physical attack on our premises.
- Vulnerabilities in the systems of our hosting or email providers. Please report those to the provider concerned.
- Output from automated scanners with no demonstrated impact, and findings that are best-practice suggestions rather than an exploitable issue.
How to report
Email contact@conformiteassist.com with the subject line “Security disclosure”. To help us act quickly, please include as much of the following as you can.
- A clear description of the issue, and the affected URL or endpoint.
- The steps needed to reproduce it, with a proof of concept if you have one.
- What an attacker could realistically achieve by exploiting it.
- Supporting evidence, such as screenshots or request and response logs.
- Whether you would like to be credited, and the name you would like us to use.
Rules we ask you to follow
- Act in good faith, and avoid any privacy violation or disruption to our service.
- Use only your own test data. Do not access, modify, copy or delete data that is not yours.
- Stop as soon as you have confirmed a vulnerability, and go no further than is needed to demonstrate it.
- Keep the issue confidential, and give us a reasonable opportunity to fix it before disclosing it to anyone else.
What you can expect from us
- We will acknowledge your report.
- We will investigate it, tell you what we find, and keep you updated while we work on a fix.
- We will let you know once the issue is resolved.
- We will credit you for the finding if you would like us to.
Safe harbour
If you report a vulnerability in good faith and follow the rules set out above, we will treat your research as authorised. We will not pursue or support legal action against you in connection with it. If a third party brings action against you for research that followed this policy, we will make it known that your activity was carried out in accordance with it.
Recognition
We do not operate a paid bug bounty programme. We are grateful for responsible disclosure, and we are glad to acknowledge the researchers who help us improve.
Contact us
Conformite Assist, Hyderabad, India. To report a security concern, email contact@conformiteassist.com.