Security

Reporting a security problem

Last updated 15 September 2026

If you think you have found a security vulnerability in Cardonomics, please tell us. We read every report, and we will not take action against people who look for problems in good faith and report them to us responsibly.

How to report

Email [email protected]. Please include:

Please do not report vulnerabilities through public channels, social media or support tickets. Our machine-readable contact file is at /.well-known/security.txt.

What is in scope

Out of scope

Testing rules

Safe harbor

If you make a good-faith effort to follow this policy while researching and reporting a vulnerability, we will consider your research authorised. We will not bring legal action against you, and we will not report you to law enforcement, for that research. If a third party takes legal action against you for research that followed this policy, we will make it known that your actions were authorised by us.

This does not cover actions that break these rules or the law in other ways, such as accessing other people's data, extortion, or disrupting the service. We cannot authorise testing of systems that belong to other companies. If you are unsure whether something is allowed, ask us first.

What happens after you report

We do not currently run a paid bug bounty. With your permission, we are happy to thank you by name once a problem is fixed.

More about how we protect data

Our Privacy Notice describes the security measures we use and what we do if personal information is ever exposed.