Legal & trust

Security & vulnerability disclosure policy

Last reviewed· Reviewed when the practice it describes changes.

Why publish this?

This desk builds vulnerability-intake processes for clients under CRA Article 14. This page and the machine-readable security.txt are that artefact, deployed on the desk's own site — inspect them as a sample of the work.

Scope

sophura.com and its subdomains. This is a static site with no accounts, no database and no third-party scripts, so the interesting surface is small — headers, hosting configuration, and anything I got wrong anyway.

How to report

Email hello@sophura.com with steps to reproduce. Acknowledgement within one business day; a substantive response — fix, timeline, or reasoned disagreement — within seven days. If a report is valid, you will be credited here if you want to be.

Safe harbour

Good-faith research within scope — no data exfiltration, no service disruption, no access to others' data — will not be met with legal action by Sophura LLC. Please give a reasonable window to fix before public disclosure; the same courtesy this desk's clients are taught to offer.

Out of scope

  • Volumetric denial-of-service findings.
  • Reports from automated scanners with no demonstrated impact.
  • Issues in the hosting provider's own infrastructure — report those to the provider, though a heads-up here is welcome.