← All statements

_Legal & statements_

Responsible Disclosure Statement

How to report a security vulnerability in our website or services, what we commit to in return, and what is out of scope.

Last updated 3 August 2026

Security by design is one of our core service lines. We welcome reports from security researchers and treat them as a contribution, not a complaint.

If you believe you have found a vulnerability in our website or in a service we operate, please tell us before disclosing it publicly.

01How to report

  • Email sales@saleostech.com with the subject line "Security disclosure".
  • Include the affected URL or endpoint, the class of issue, and clear steps to reproduce.
  • Include the potential impact, and any proof-of-concept material as an attachment rather than a public link.
  • Tell us how you would like to be credited, if at all.

02What we commit to

  • Acknowledge your report within 3 working days.
  • Provide an initial assessment and expected remediation timeline within 10 working days.
  • Keep you updated while we work on a fix, and confirm when it is resolved.
  • Credit you publicly if you would like us to, once the issue is fixed.

03What we ask

  • Give us a reasonable opportunity to fix the issue before any public disclosure. We suggest 90 days.
  • Do not access, modify, or delete data that is not yours, and stop at the point you have proven the issue.
  • Do not run automated scanning that degrades availability, and do not attempt denial-of-service or social engineering against our people or clients.
  • Comply with applicable law, including the Computer Misuse Act 1990 and data protection law.

04Safe harbour

If you follow this statement in good faith, we will not pursue or support legal action against you for your research, and we will make that position clear if a third party raises the matter with us.

We do not currently operate a paid bug bounty.

05Out of scope

  • Findings from automated scanners without a demonstrated, exploitable impact.
  • Missing best-practice headers or TLS configuration with no proven exploit path.
  • Rate limiting or brute-force issues on non-authenticated forms.
  • Social engineering, phishing, or physical attacks against our staff or offices.
  • Vulnerabilities in third-party services we do not operate. Please report those to the relevant vendor.