Vulnerability Disclosure Policy
NeedSec welcomes good-faith reports that help us protect our website, systems, and users. This policy explains how to report a suspected vulnerability safely and what you can expect from us.
Last updated: 28 July 2026
Report a vulnerability
Email your report to hello@needsec.com. Use the subject line "Responsible vulnerability disclosure" and do not send passwords, private keys, or unnecessary personal data.
What happens next
We aim to acknowledge a valid report within 48 hours. We will review the evidence, keep you informed where practical, and coordinate any remediation and responsible publication timing with you.
What to include
Clear, focused reports help us validate and remediate issues quickly.
- The affected NeedSec URL, system, feature, or endpoint.
- A clear description of the issue and its potential impact.
- Steps that allow us to reproduce the issue safely.
- Supporting evidence such as requests, responses, screenshots, or proof-of-concept code.
- Your preferred contact details and whether you want to be credited.
Research guidelines
Please follow these boundaries so your research remains safe, proportionate, and respectful of other people.
- Only test systems and data that you own or have explicit permission to access.
- Use the minimum testing needed to confirm the issue and avoid disrupting services.
- Do not access, retain, alter, delete, or disclose another person's data.
- Do not use denial-of-service, social engineering, phishing, spam, malware, or physical attacks.
- Stop testing and contact us immediately if you encounter sensitive or personal data.
- Keep vulnerability details confidential while we investigate and coordinate remediation.
Out of scope
We still welcome context where you believe an item presents material risk, but the following reports are usually not actionable on their own.
- Reports based only on missing optional headers or automated scanner output without demonstrated impact.
- Clickjacking on pages that do not perform sensitive actions.
- Self-XSS, content spoofing, or rate-limit observations without a credible security impact.
- Issues in third-party services that are not controlled by NeedSec.
- Previously reported issues, known issues already being remediated, or unsupported software versions.
Good-faith handling
If you act in good faith, stay within this policy, and comply with applicable law, NeedSec will treat your report as responsible security research and work with you to understand the issue.
This policy does not authorise testing of client environments, third-party systems, or any asset you do not have permission to test. If you are unsure whether a system is in scope, contact us before testing.