Security and responsible disclosure
Last updated: 6 October 2026
Reporting a vulnerability
If you believe you have found a security issue in a Rabbitnose service, email security@rabbitnose.com with a clear description, the affected URL and steps to reproduce. We aim to reply within five working days.
Scope
In scope: rabbitnose.com and services we operate. Out of scope: reports from automated scanners without a demonstrated impact, missing best-practice headers or records without a working exploit, clickjacking on pages with no sensitive actions, denial-of-service, social engineering, and physical attacks.
Rules
Do not access, change or delete data that is not yours, do not degrade our services, and give us reasonable time to fix an issue before any disclosure. Testing within these rules in good faith will not lead to action from us.
Rewards
We do not run a paid bug bounty programme and do not pay for unsolicited reports. Valid, impactful findings are acknowledged with thanks.