Control Edge AB ("we," "us," "our") takes the security of CppModel seriously. We welcome reports from security researchers who discover vulnerabilities in our products and services, and we are committed to working with you to understand and resolve issues quickly.
This policy applies to:
Third-party services we rely on (for example our payment processor, scheduling tool, or identity provider) are out of scope. Please report vulnerabilities in those services directly to the respective vendor.
Email [email protected] with:
Please do not include real customer data in your report. If you believe your finding affects customer data, describe the issue without including the data itself.
When researching a potential vulnerability, please:
We ask that you give us 90 days from your initial report to investigate and remediate the issue before making any public disclosure, and that we coordinate with you on the timing and content of any public writeup. If a fix requires more time, we will communicate this and work with you on a mutually agreeable timeline.
We will not pursue legal action against researchers who discover and report vulnerabilities in good faith, in accordance with this policy, and who provide us a reasonable opportunity to investigate and remediate the issue before any public disclosure. This safe harbor does not extend to testing that violates the rules described in Section 4, or to actions that violate applicable law.
We may update this Security Policy from time to time. We will post the updated policy on our website.
If you have any questions about this Security Policy, please contact us at [email protected].