Responsible Disclosure Policy
Audentes Fortuna is committed to maintaining the security of our systems and protecting the privacy of our clients and employees. We appreciate the security research community and recognize the important role that security researchers play in keeping our systems secure.
Scope
This policy applies to security vulnerabilities found in:
- Our public-facing websites and applications
- Our client portals and systems
- Our internal security infrastructure
- Any systems operated by Audentes Fortuna
What We're Looking For
We encourage responsible disclosure of security vulnerabilities including:
- Cross-site scripting (XSS)
- SQL injection
- Authentication and authorization flaws
- Server-side request forgery (SSRF)
- Remote code execution
- Information disclosure
- Business logic vulnerabilities
What We're NOT Looking For
Please do not report:
- Social engineering attacks
- Physical security issues
- Denial of service attacks
- Spam or social engineering
- Issues in third-party applications
- Outdated software versions without proof of exploitability
How to Report
To report a security vulnerability, please:
- Email your findings to security@audentesfortuna.co.uk
- Include detailed steps to reproduce the vulnerability
- Provide screenshots or proof-of-concept code if applicable
- Include your contact information for follow-up
What to Expect
When you report a vulnerability:
- Initial Response: We will acknowledge receipt within 48 hours
- Assessment: We will assess the vulnerability within 5 business days
- Resolution: We will work to resolve critical issues within 30 days
- Updates: We will provide regular updates on our progress
Safe Harbor
We will not pursue legal action against security researchers who:
- Act in good faith and in accordance with this policy
- Do not access or modify data beyond what is necessary to demonstrate the vulnerability
- Do not cause harm to our systems or users
- Do not publicly disclose the vulnerability before we have had a chance to fix it
Recognition
We appreciate security researchers who help us improve our security posture. While we do not offer monetary rewards, we may:
- Publicly acknowledge your contribution (with your permission)
- Provide a certificate of appreciation
- Consider you for future security consulting opportunities
Out of Scope
The following are considered out of scope for this program:
- Social engineering attacks against our employees
- Physical security assessments
- Denial of service attacks
- Issues in third-party services we use
- Vulnerabilities in outdated software without proof of exploitability
Contact Information
For security-related inquiries, please contact:
- Security Team: security@audentesfortuna.co.uk
- Emergency Contact: +44 20 XXXX XXXX
- Address: London, United Kingdom
Important: This policy is not a license to test our systems. We reserve the right to modify this policy at any time.
Last Updated: November 8, 2025