Helping us keep Apperah secure
We welcome reports from security researchers. If you’ve found a security vulnerability in Apperah, please tell us so we can fix it. This policy explains how to report and what you can expect from us.
Safe harbour
If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research (including under computer-misuse laws), and we will treat your report as authorised access for the purposes of that research. This safe harbour does not apply if you break the rules below or break the law.
How to report
Email security@apperah.com with:
- a description of the vulnerability and where it is,
- the steps to reproduce it,
- the potential impact, and
- any proof-of-concept (please don’t include real personal data of others).
The rules
- Don’t harm others’ data or privacy — don’t access, modify, delete, or download other people’s data beyond the minimum needed to demonstrate the issue.
- Don’t disrupt the service — no denial-of-service, spam, or automated testing that degrades Apperah for others.
- No social engineering or physical attacks — don’t target our staff, users, or offices.
- Give us time — please report privately and give us a reasonable period to fix the issue before disclosing it publicly (coordinated disclosure).
What we commit to
- Acknowledge your report promptly.
- Investigate and fix valid issues, keeping you updated.
- Credit you for the discovery if you wish (and where appropriate).
We do not currently operate a paid bug-bounty programme.