Vulnerability Disclosure Policy
1. Introduction
1.1.
Setyl Ltd (Setyl, we, us or our) takes the security of our platform and our customers’ data seriously. We value the work of security researchers, and we welcome reports of security vulnerabilities so that we can address them responsibly.
1.2.
This policy explains how to report a vulnerability to us, what we ask of you, and what you can expect from us in return.
2. Scope
2.1.
This policy applies to security vulnerabilities discovered in:
the Setyl platform at app.setyl.com;
our website at setyl.com;
our API and developer services; and
other systems and services that we clearly own and operate.
2.2.
Out of scope: third-party services we do not control, sub-processors’ own systems, findings from automated scanners without a demonstrated impact, and reports relating solely to missing best-practice hardening without a realistic exploit (for example, reports about email SPF/DKIM configuration, rate-limiting, or software version numbers). If in doubt, report it and we will let you know.
3. How to report
3.1.
Please send your report to security@setyl.com, or use the contact details in our security.txt file at setyl.com/.well-known/security.txt.
3.2.
To help us assess and reproduce the issue quickly, please include:
a clear description of the vulnerability and its potential impact;
the steps required to reproduce it, including any proof-of-concept;
the affected URL, endpoint, or component; and
any relevant screenshots, logs, or request/response captures.
4. Guidelines for researchers
4.1.
When investigating and reporting a vulnerability, we ask that you:
act in good faith and avoid any activity that could harm the platform, our customers, or their data;
do not access, modify, delete, or exfiltrate data that does not belong to you — use only test accounts you control, and only interact with your own data;
do not perform testing that degrades or disrupts our services, such as denial-of-service, spam, or high-volume automated testing;
do not use social engineering, phishing, or physical attacks against our staff, customers, or facilities;
keep the details of any vulnerability confidential until we have had a reasonable opportunity to remediate it, and coordinate any public disclosure with us; and
comply with all applicable laws.
5. Our commitment to you
5.1.
If you make a good-faith effort to comply with this policy when reporting a vulnerability, we will:
acknowledge receipt of your report, normally within 5 Business Days;
work with you to understand and validate the issue, and keep you reasonably informed of our progress;
aim to remediate confirmed vulnerabilities in a timeframe appropriate to their severity; and
not pursue or support legal action against you in relation to your research, provided you acted in accordance with this policy.
5.2.
We are grateful to researchers who help us keep our platform secure. While we do not currently operate a paid bug bounty programme, we are happy to acknowledge your contribution (with your consent) once an issue has been resolved.
6. Safe harbour
6.1.
We consider security research and vulnerability disclosure conducted in accordance with this policy to be authorised, and we will not treat it as a breach of our Acceptable Use Policy or terms of service. This policy does not, and cannot, authorise any activity that would breach the rights of third parties or applicable law, and it does not bind any third party.
7. Contact
7.1.
For all security reports and questions about this policy, contact us at security@setyl.com.