NeedSec logo
Responsible disclosure

Vulnerability Disclosure Policy

NeedSec welcomes good-faith reports that help us protect our website, systems, and users. This policy explains how to report a suspected vulnerability safely and what you can expect from us.

Last updated: 28 July 2026

Report a vulnerability

Email your report to hello@needsec.com. Use the subject line "Responsible vulnerability disclosure" and do not send passwords, private keys, or unnecessary personal data.

What happens next

We aim to acknowledge a valid report within 48 hours. We will review the evidence, keep you informed where practical, and coordinate any remediation and responsible publication timing with you.

What to include

Clear, focused reports help us validate and remediate issues quickly.

  • The affected NeedSec URL, system, feature, or endpoint.
  • A clear description of the issue and its potential impact.
  • Steps that allow us to reproduce the issue safely.
  • Supporting evidence such as requests, responses, screenshots, or proof-of-concept code.
  • Your preferred contact details and whether you want to be credited.

Research guidelines

Please follow these boundaries so your research remains safe, proportionate, and respectful of other people.

Out of scope

We still welcome context where you believe an item presents material risk, but the following reports are usually not actionable on their own.

  • Reports based only on missing optional headers or automated scanner output without demonstrated impact.
  • Clickjacking on pages that do not perform sensitive actions.
  • Self-XSS, content spoofing, or rate-limit observations without a credible security impact.
  • Issues in third-party services that are not controlled by NeedSec.
  • Previously reported issues, known issues already being remediated, or unsupported software versions.

Good-faith handling

If you act in good faith, stay within this policy, and comply with applicable law, NeedSec will treat your report as responsible security research and work with you to understand the issue.

This policy does not authorise testing of client environments, third-party systems, or any asset you do not have permission to test. If you are unsure whether a system is in scope, contact us before testing.

Contact NeedSec