Found a weak spot? Tell us.
We welcome every report made in good faith. If you found a vulnerability on our site or on a system we run, let us know and we will fix it.

How to report
Email [email protected].
If you can, encrypt your message with our PGP key. Download the key
Or use the contact form and pick the “Security report” topic.
What to include
- The affected URL or system.
- A short description of the issue.
- Steps to reproduce it, so we can see it too.
- The impact: what an attacker could do with it.
- A proof of concept, if you have one. Keep it harmless.
What is in scope
We want to hear about issues on:
- uptools.io and all of its subdomains.
- Client sites we run whose security.txt points here.
Not sure whether a site is ours? Check its /.well-known/security.txt. If it points here, you are in the right place.
What we do not treat as a vulnerability
These can be useful hints, but on their own they are not a risk. If you can actually exploit one, show us how.
- Missing security headers without a concrete way to exploit them.
- SPF, DKIM or DMARC suggestions.
- Clickjacking on pages with no sensitive action.
- A software version number on its own.
- Unverified output from automated scanners.
- Missing rate limiting on endpoints that are not sensitive.
- Self-XSS that only works in your own browser.
- CSRF on logout.
Please do not
Your testing should never harm us or our clients.
- Run denial of service (DoS) or load tests.
- Use social engineering on our team or our clients.
- Try to get physical access to offices, servers or devices.
- View, change or delete other users’ data. If you get access by accident, stop and tell us.
- Send spam.
- Run automated mass scans.
What we promise
- 1
Within one business day
we confirm that your report has arrived.
- 2
Within 10 business days
you get a first real assessment: how serious it is and what we plan to do.
- 3
Along the way
we keep you posted on the fix and tell you when it is done.
- 4
Disclosure, together
Please keep it private until it is fixed. Our default deadline is 90 days.
Research in good faith
If you follow this policy and stay within the limits above on systems we own or are authorized to test, we consider your research authorized. We will not report you or bring a civil claim because of that research, unless the law requires us to. This does not bind the authorities or anyone else. Client systems are covered only where the client has authorized us to permit testing.
Rewards
We do not pay bounties. If you like, we will thank you publicly, by name or alias.
If you ask for payment before sharing the details, we cannot work with you.
For machines, too
The same, in short, in the standard security.txt format. This is what security tools read.
Contact: mailto:[email protected]Contact: https://uptools.io/hu/contact/?topic=securityExpires: 2027-10-05T00:00:00.000ZEncryption: https://uptools.io/.well-known/pgp-key.txtPreferred-Languages: hu, enPolicy: https://uptools.io/security/Canonical: https://uptools.io/.well-known/security.txt