Legal
Responsible Disclosure
If you have found a security issue in our own systems, we want to hear about it — and we will treat you well for telling us.
Last updated: 7 September 2026
Reporting
Email info@astracybertech.com with “Security disclosure” in the subject line. Include enough detail to reproduce the issue: the affected URL or component, the steps, and what an attacker could achieve. Proof-of-concept code and screenshots help.
What we commit to
- We acknowledge reports within two business days.
- We give you an assessment and an expected remediation timeline within ten business days.
- We keep you updated until the issue is closed.
- We will credit you publicly if you would like us to, and will not take legal action against researchers who follow this policy in good faith.
Scope
Systems operated by us and reachable from the internet under our own domains. Please exercise care with third-party services we use but do not control, and report issues in those to the vendor.
Out of scope
- Client systems. We test those under contract; if you believe you have found something in a client environment, contact the client.
- Denial of service, volumetric testing, and anything that degrades availability for other users.
- Social engineering of our staff, and physical attacks on our offices.
- Reports generated solely by an automated scanner with no demonstrated impact, and findings limited to missing best-practice headers with no exploitable consequence.
Ground rules
Work only against your own accounts and data. Do not access, modify or exfiltrate anyone else’s information. Stop as soon as you have established that an issue exists, and give us a reasonable opportunity to fix it before disclosing publicly.
A machine-readable version of this policy is published at /.well-known/security.txt.

