Last reviewed· Reviewed when the practice it describes changes.
Why publish this?
This desk builds vulnerability-intake processes for clients under CRA Article 14. This page and the machine-readable security.txt are that artefact, deployed on the desk's own site — inspect them as a sample of the work.
Scope
sophura.com and its subdomains. This is a static site with no accounts, no database and no third-party scripts, so the interesting surface is small — headers, hosting configuration, and anything I got wrong anyway.
How to report
Email hello@sophura.com with steps to reproduce. Acknowledgement within one business day; a substantive response — fix, timeline, or reasoned disagreement — within seven days. If a report is valid, you will be credited here if you want to be.
Safe harbour
Good-faith research within scope — no data exfiltration, no service disruption, no access to others' data — will not be met with legal action by Sophura LLC. Please give a reasonable window to fix before public disclosure; the same courtesy this desk's clients are taught to offer.
Out of scope
- Volumetric denial-of-service findings.
- Reports from automated scanners with no demonstrated impact.
- Issues in the hosting provider's own infrastructure — report those to the provider, though a heads-up here is welcome.