FinStitch← Back to home

Responsible Disclosure

Last updated 19 June 2026

Protecting our platform and our users' information is one of our highest priorities. We welcome responsible security research and appreciate everyone who helps us identify and disclose vulnerabilities responsibly.

1. Reporting a security vulnerability

If you believe you've found a security vulnerability affecting FinStitch, email our security team at security@finstitch.com. Please include as much detail as possible so we can investigate efficiently. Where applicable, your report should include:

  • A clear description of the vulnerability.
  • Steps required to reproduce the issue.
  • The affected page, endpoint or feature.
  • The potential security impact.
  • Screenshots or proof of concept, where appropriate.
  • Any supporting logs or technical information.
  • Your preferred contact details.

2. What we ask of security researchers

When researching security issues involving FinStitch, we ask that you:

  • Act in good faith.
  • Avoid causing harm to users or the platform.
  • Respect the privacy of our users.
  • Do not access, modify, copy or delete data that does not belong to you.
  • Do not disrupt the availability or performance of our Services.
  • Avoid automated testing that could affect system stability.
  • Report vulnerabilities promptly after discovery.
  • Give us a reasonable opportunity to investigate and fix the issue before any public disclosure.

3. Out of scope

Unless specifically authorised by FinStitch, the following are generally outside the scope of this policy:

  • Social engineering attacks.
  • Phishing campaigns.
  • Physical attacks.
  • Distributed denial-of-service (DDoS) attacks.
  • Spam or email abuse.
  • Automated scanning that degrades service performance.
  • Vulnerabilities in third-party services outside FinStitch's control.
  • Reports based solely on missing HTTP headers or best-practice recommendations without a demonstrable security impact.
  • Reports relating to outdated browsers or unsupported software.

4. Our response process

When you submit a valid vulnerability report, we aim to:

StageTarget
Acknowledge receipt of your reportWithin 3 business days
Perform an initial assessmentWithin 7 business days
Keep you informed of material progress where appropriateThroughout the investigation
Resolve confirmed vulnerabilitiesAs quickly as reasonably practicable, based on severity and complexity

These response times are targets rather than guarantees, and may vary depending on the nature of the report.

5. Safe harbour

If you act in good faith, comply with this policy, avoid intentionally harming users or our Services, and promptly report vulnerabilities to us, we will not pursue legal action against you solely for security research conducted in accordance with this policy. This safe harbour applies only to activities consistent with this policy and applicable law.

6. Recognition

We greatly appreciate the security community. Although FinStitch does not currently operate a public bug-bounty programme, we may acknowledge researchers who responsibly disclose significant vulnerabilities, at our discretion and on a case-by-case basis.

7. Related resources

For more on how we protect customer information, see our:

  • Security page.
  • Privacy Policy.
  • GDPR & Your Rights.
  • Subprocessors.

8. Contact

For all security-related matters, including vulnerability reports, contact our security team at security@finstitch.com. For general help, support@finstitch.com.

© 2026 FinStitch
Trust CenterSecurityPrivacyTermsHome