SIGNALNINE Security

Reporting a vulnerability

Effective 8 August 2026

We ask other people to take our findings seriously, so we take yours the same way. If you have found a security issue in anything we run, tell us and we will act on it.

Email contact@signalnine.org with enough detail to reproduce the issue. Machine-readable contact details are published at /.well-known/security.txt.

What we commit to

  • We acknowledge reports within two business days.
  • We tell you our assessment, including if we disagree that it is a vulnerability.
  • We will not take legal action over good-faith research within the scope below.
  • We credit reporters who want credit, and stay quiet about those who do not.

Scope

In scope: signalnine.org and the customer portal.

Out of scope: our customers' systems, anything reachable only through a customer's data, denial-of-service and volumetric testing, social engineering of our staff or suppliers, and findings in third-party services we consume, which should be reported to the vendor.

Please use your own test account, do not access other people's data, and stop as soon as you have shown the issue exists. If you access customer data by accident, stop and tell us rather than exploring further.

No bounty

We do not run a paid bounty program, and we would rather say so than imply one. You will get a fast, technically competent response from someone who does this for a living.