Vulnerability disclosure policy

Last updated: 22 July 2026 · Machine-readable version: /.well-known/security.txt

We fix other people’s bugs for a living, so we take reports about our own seriously, and gratefully. If you’ve found a security issue in anything we run, we want to hear about it.

Scope

Out of scope: our clients’ websites and systems (report those to the client), denial-of-service testing, social engineering, physical attacks, and spam/SPF/DMARC-only reports without demonstrated impact.

How to report

Email security@accesspatched.com with enough detail to reproduce the issue: affected URL or component, steps, and impact as you understand it. PGP available on request. Please don’t include more personal data than needed in the report.

What we promise

Safe harbor

If you make a good-faith effort to comply with this policy (no privacy violations, no data destruction, no service disruption, access limited to the minimum needed to demonstrate the issue, and no public disclosure before we’ve had the 90-day window), we will consider your research authorized, will not initiate legal action against you, and will say so plainly if anyone else asks. If in doubt about whether something is in scope, ask first.

No bounty (yet)

We’re a small company and don’t run a paid bounty program at this time. We do offer sincere thanks, public credit, and the warm feeling of having out-audited the auditors.