Vulnerability Disclosure Policy
Version 1.0 · Last updated 23 September 2026
We want to hear about security problems in Tidehawk before anyone else does. If you have found one, this page tells you how to report it, what we will do, and what we ask of you.
1. How to report
Email security@tidehawk.co with enough detail for us to reproduce the issue: the URL or component, the steps you took, and what you observed. Please do not include other people's data in the report. We acknowledge reports within one working day and aim to give you an initial assessment within five working days.
2. What we ask of you
- Test only against accounts you own or a trial workspace you created for the purpose.
- Stop as soon as you have confirmed the issue. Do not access, change or download data that is not yours.
- Do not run denial-of-service tests, automated scanners at high rates, or social engineering against our staff or customers.
- Give us a reasonable time to fix the issue before disclosing it publicly. We ask for 90 days, or longer by agreement for issues that need it.
- Do not demand payment for a report. We do not run a paid bounty programme at present.
3. What we promise
Safe harbour
If you follow this policy in good faith, we will not take legal action against you or report you to law enforcement for your research, and we will treat your activity as authorised for the purposes of the Computer Misuse Act 1990 and our Acceptable Use Policy. If a third party takes action against you for research that complied with this policy, we will make it known that your activity was authorised.
We will keep you informed of our progress, tell you when the issue is fixed, and, if you wish, credit you publicly once it is. We will not share your details with anyone else without your permission.
4. Scope
In scope: app.tidehawk.co, docs.tidehawk.co, tidehawk.co and the APIs behind them. Out of scope: our third-party providers (report those to the provider), attacks that need physical access or a compromised device, missing best-practice headers with no demonstrated impact, and reports generated by automated tools without a working proof of concept.
5. Our security details
This policy is also published at /.well-known/security.txt. For how we protect customer data generally, see our security page.