Security disclosure policy
RiskFinder bygger værktøjer til kritisk infrastruktur. Vi tager sikkerhedsfejl alvorligt og værdsætter ansvarlig afsløring fra researchere, kunder og samarbejdspartnere.
How to report a vulnerability
If you believe you have found a security vulnerability in RiskFinder – in the marketing site, the application, our API endpoints or our infrastructure – please report it to us privately:
- Email: [email protected] (preferred)
- Backup: [email protected]
- Languages: Dansk, English
- Machine-readable policy:
/.well-known/security.txt
Please include enough detail for us to reproduce the issue: a description, steps to reproduce, the affected URL or endpoint, and ideally a proof-of-concept. Encrypted messages are welcome – ask us for a current PGP key.
Our response timelines
- Within 3 business days – acknowledgment of your report
- Within 14 days – initial triage with severity assessment
- Critical issues – mitigation typically within 7 days
- Coordinated disclosure – default 90 days from report; we will negotiate longer if a fix requires it, and we will not pressure you to delay disclosure beyond what is reasonable
- Public credit – for valid, previously unreported findings we assess as High or Critical severity (CVSS 7.0+) with a demonstrated, reproducible impact, we will acknowledge your contribution publicly after the fix has shipped, with your permission
No bug bounty – but real gratitude
RiskFinder does not currently run a paid bug bounty programme. We read and respond to every report, including automated scan results. Public acknowledgment is reserved for valid, previously unreported findings that we assess as High or Critical severity (CVSS 7.0+) with a demonstrated, reproducible impact; RiskFinder decides the severity. Those findings also earn a written letter of thanks, RiskFinder swag and a beer if you're ever in København.
What is in scope
Anything we operate is in scope, including but not limited to:
www.riskfinder.dkandriskfinder.dk(this site)- API endpoints under
/api/(Cloudflare Workers) - The RiskFinder application (subdomain to be confirmed during disclosure)
- Email and authentication infrastructure operated by RiskFinder
Out of scope: third-party services we do not operate (Cloudflare, Resend, GitHub, PostHog, Google Analytics) – please report those directly to the vendor. Volumetric DoS, social engineering of staff, and physical attacks are also out of scope.
Especially welcome
Findings related to our preparedness and risk-management platform are especially welcome. We ship a security tool, and integrity matters more than ego. Authentication bypasses, IDOR, SSRF, RCE, broken access control, secret exposure, and supply-chain risks are the categories we most want to hear about.
Safe-harbor commitment
We will not pursue civil or criminal action against researchers who, in good faith:
- Test only on accounts and data they own, or that we have explicitly authorised them to test
- Avoid privacy violations, service disruption, and data destruction
- Report findings privately to us before public disclosure, and give us reasonable time to respond
- Do not exfiltrate more data than is strictly necessary to demonstrate the vulnerability
Safe harbor applies to all good-faith research, whatever the severity of the finding.
If in doubt about whether your testing is in scope or in good faith, email us first – we are happy to clarify.
Machine-readable policy
This page is the human-readable security policy. The machine-readable equivalent (RFC 9116) is at /.well-known/security.txt and lists current contact addresses, expiration date and preferred languages.