Trust

Reporting a vulnerability

We would rather hear about a security issue from you than discover it the hard way. Here is how to tell us.

At Numerico Technologies, we take the security of our website and software products very seriously. We recognise that no system can be one hundred percent secure, and we are committed to promptly addressing any security issues reported to us by security researchers or other third parties.

To that end, we have established a coordinated vulnerability disclosure process, which outlines how we receive, triage, and respond to reports of potential security vulnerabilities.

How to report

If you believe you have discovered a security vulnerability in our website or software products, we encourage you to report it in accordance with our disclosure process. This allows us to work with you to investigate and remediate the issue, while minimising the risk of exploitation by malicious actors.

Please include a detailed description of the vulnerability, along with any steps necessary to reproduce it. We also encourage you to provide supporting material, such as proof-of-concept code or screenshots, to help us better understand the issue.

What happens next

Upon receipt of your report, we will promptly acknowledge it and begin our triage process. This may involve reaching out to you for additional information or clarification. Once we have verified the vulnerability, we will work with you to develop a timeline for remediation, and keep you updated on our progress.

Recognition

As a token of our appreciation for responsible reporting, Numerico Technologies may offer monetary or non-monetary rewards to individuals who submit valid and useful reports. The decision to grant a reward is based on the impact and risk of the report, and is made at the discretion of Numerico Technologies.

Out of scope

The following issues are considered out of scope:

  • An anomaly that has no impact on the availability, integrity or confidentiality of information.
  • The availability of version information on a static website.
  • The absence of HTTP security headers such as those used by Cross-Origin Resource Sharing, unless it is evident that this leads to a security issue.

We are committed to working with the security community to ensure the safety and security of our customers and users. Thank you for your help in keeping our website and software products secure.