Vulnerability disclosure policy
Last updated: 22 July 2026 · Machine-readable version: /.well-known/security.txt
We fix other people’s bugs for a living, so we take reports about our own seriously, and gratefully. If you’ve found a security issue in anything we run, we want to hear about it.
Scope
- accesspatched.com and its subdomains
- Infrastructure and tooling we operate for delivering our services
Out of scope: our clients’ websites and systems (report those to the client), denial-of-service testing, social engineering, physical attacks, and spam/SPF/DMARC-only reports without demonstrated impact.
How to report
Email security@accesspatched.com with enough detail to reproduce the issue: affected URL or component, steps, and impact as you understand it. PGP available on request. Please don’t include more personal data than needed in the report.
What we promise
- Acknowledgement within 3 business days.
- An assessment and expected timeline within 10 business days.
- A fix or mitigation for confirmed issues within 90 days (usually far sooner; patching is rather our thing).
- We’ll keep you informed and credit you in our acknowledgements if you’d like (or keep you anonymous if you prefer).
Safe harbor
If you make a good-faith effort to comply with this policy (no privacy violations, no data destruction, no service disruption, access limited to the minimum needed to demonstrate the issue, and no public disclosure before we’ve had the 90-day window), we will consider your research authorized, will not initiate legal action against you, and will say so plainly if anyone else asks. If in doubt about whether something is in scope, ask first.
No bounty (yet)
We’re a small company and don’t run a paid bounty program at this time. We do offer sincere thanks, public credit, and the warm feeling of having out-audited the auditors.