Legal
Responsible Disclosure
Last updated 9 August 2026
We test other people's systems for a living, so we take reports about our own seriously. If you have found something, we want to hear about it and we will not be difficult about it.
How to report
Email security@aptsecuritymanagement.com. Machine readable details are at /.well-known/security.txt.
Useful things to include, none of them mandatory:
- What you found and where
- Steps to reproduce it, or a proof of concept
- What an attacker could do with it
- How you would like to be credited, or that you would rather not be
What we commit to
- Acknowledgement within two business days. From a person, not an autoresponder
- An assessment within ten business days, including whether we agree with your severity
- Credit if you want it, and silence if you do not
- No legal action against anyone acting in good faith under this policy
- A straight answer if we decide not to fix something, including why
In scope
www.aptsecuritymanagement.comand this site's infrastructure- Our free tool subdomains under
aptsecuritymanagement.com - Our email and DNS configuration
Out of scope
Client systems, always. If you have found something in a system we tested, report it to its owner. We cannot authorise testing of anything that is not ours, and neither can you.
Also out of scope:
- Findings from automated scanners with no demonstrated impact
- Missing headers or configuration weaknesses with no exploitable consequence
- Social engineering of our staff, or physical attacks
- Denial of service, volumetric testing, or anything that degrades the service for others
- Reports about third-party services we use, which belong with those vendors
Rules
Act in good faith. Do not access, modify or delete data that is not yours. Do not degrade the service. Give us reasonable time to fix something before publishing, and tell us your intended timeline so we can meet it.
Bounties
We do not currently run a paid bounty program. We are a two-person firm and would rather be honest about that than advertise a reward we cannot fund consistently. Credit, a genuine thank you, and a fast response are what we can offer.
