Skip to main content

Security

Last updated: 6 October 2026

Help us keep the LEONIS website safe. If you find a possible vulnerability, report it privately so we can investigate and coordinate a fix.

1. How to report

Send a concise description of the issue and its potential impact. Include the affected URL, steps to reproduce it, and a minimal proof of concept or redacted screenshots where useful. Tell us how to contact you and whether you would like public credit.

Do not email passwords, access tokens, personal data belonging to others or confidential client material. If evidence needs a protected transfer channel, send a high-level description first so we can agree a suitable method.

2. What is in scope

This policy covers the public website content and configuration that LEONIS operates on these hosts:

  • www.leonisresilience.com — the LEONIS website.
  • leonisresilience.com — the redirect to the main website.
  • mta-sts.leonisresilience.com — the published mail transport security policy.

3. Boundaries for testing

This policy does not authorise testing of email accounts, client systems, other subdomains, Vercel infrastructure or any third-party service. ReadinessNavigator has its own reporting policy. If you are unsure about scope, contact us before testing.

  • Do not perform denial-of-service, load or stress tests, high-volume automated scanning, phishing, social engineering or physical attacks.
  • Use only accounts and data you control. Do not access, change, download or disclose another person’s data, establish persistence, or move into other systems.
  • Stop once you have enough evidence. If you encounter personal data or an unexpected impact on the service, stop immediately and report it with minimal detail.
  • Explain practical impact. A scanner alert or missing header alone may not demonstrate a vulnerability, but you can report a concern without attempting harmful exploitation.

4. What happens next

We aim to acknowledge your report within five working days. We will assess the issue, ask for clarification where needed, and keep you informed of material progress. This is a response target, not a guaranteed resolution deadline.

Please keep the report and evidence private while we investigate. We will work with you on an appropriate disclosure date once a fix or mitigation is ready, taking severity and the interests of affected people into account. If we have not acknowledged your report after five working days, please follow up in the same email thread.

We can agree public acknowledgement if you would like it. We will not publish your name or contact details without your agreement. Reports do not create an entitlement to payment; we do not operate a bug bounty programme.

5. Our commitment to good-faith research

For research within the scope and boundaries above, conducted in good faith and reported promptly, LEONIS will not bring a civil claim or file a criminal complaint against you under rights within its control solely because of that research.

To rely on this commitment, avoid harm and unnecessary access, preserve confidentiality, cooperate on remediation and allow reasonable time for coordinated disclosure. Keep only the minimum evidence needed and delete sensitive evidence securely when it is no longer required for that process or by law.

This commitment applies only to LEONIS and rights it controls. It cannot bind service providers, other parties or public authorities, waive their rights, or authorise access to their systems. It does not change applicable law.

6. Your report and personal data

We use the contact information and evidence in your report to assess and resolve the issue and communicate with you. We limit sharing to people and providers who need it for those purposes, or where disclosure is legally required. Please redact unrelated personal information.

Report information is retained while needed for assessment, remediation, coordinated disclosure and follow-up, with limited evidence retained longer only where necessary for an ongoing incident, legal obligation or claim. The Privacy Policy explains the controller, legal basis, recipients, international transfers and your rights.

7. Machine-readable contact

Our security.txt file provides the reporting address and a link to this policy for researchers and automated tools. Its presence does not expand the testing scope above.