Responsible Disclosure
Last updated 19 June 2026
Protecting our platform and our users' information is one of our highest priorities. We welcome responsible security research and appreciate everyone who helps us identify and disclose vulnerabilities responsibly.
1. Reporting a security vulnerability
If you believe you've found a security vulnerability affecting FinStitch, email our security team at security@finstitch.com. Please include as much detail as possible so we can investigate efficiently. Where applicable, your report should include:
- A clear description of the vulnerability.
- Steps required to reproduce the issue.
- The affected page, endpoint or feature.
- The potential security impact.
- Screenshots or proof of concept, where appropriate.
- Any supporting logs or technical information.
- Your preferred contact details.
2. What we ask of security researchers
When researching security issues involving FinStitch, we ask that you:
- Act in good faith.
- Avoid causing harm to users or the platform.
- Respect the privacy of our users.
- Do not access, modify, copy or delete data that does not belong to you.
- Do not disrupt the availability or performance of our Services.
- Avoid automated testing that could affect system stability.
- Report vulnerabilities promptly after discovery.
- Give us a reasonable opportunity to investigate and fix the issue before any public disclosure.
3. Out of scope
Unless specifically authorised by FinStitch, the following are generally outside the scope of this policy:
- Social engineering attacks.
- Phishing campaigns.
- Physical attacks.
- Distributed denial-of-service (DDoS) attacks.
- Spam or email abuse.
- Automated scanning that degrades service performance.
- Vulnerabilities in third-party services outside FinStitch's control.
- Reports based solely on missing HTTP headers or best-practice recommendations without a demonstrable security impact.
- Reports relating to outdated browsers or unsupported software.
4. Our response process
When you submit a valid vulnerability report, we aim to:
| Stage | Target |
|---|---|
| Acknowledge receipt of your report | Within 3 business days |
| Perform an initial assessment | Within 7 business days |
| Keep you informed of material progress where appropriate | Throughout the investigation |
| Resolve confirmed vulnerabilities | As quickly as reasonably practicable, based on severity and complexity |
These response times are targets rather than guarantees, and may vary depending on the nature of the report.
5. Safe harbour
If you act in good faith, comply with this policy, avoid intentionally harming users or our Services, and promptly report vulnerabilities to us, we will not pursue legal action against you solely for security research conducted in accordance with this policy. This safe harbour applies only to activities consistent with this policy and applicable law.
6. Recognition
We greatly appreciate the security community. Although FinStitch does not currently operate a public bug-bounty programme, we may acknowledge researchers who responsibly disclose significant vulnerabilities, at our discretion and on a case-by-case basis.
7. Related resources
For more on how we protect customer information, see our:
8. Contact
For all security-related matters, including vulnerability reports, contact our security team at security@finstitch.com. For general help, support@finstitch.com.