Hacked or down? We step in within 5 hours
Let's talk
Security

Found a weak spot? Tell us.

We welcome every report made in good faith. If you found a vulnerability on our site or on a system we run, let us know and we will fix it.

Report by email[email protected]
Illustration: an open padlock showing its mechanism. A researcher points a torch at the faulty gear while two hands fit a yellow gear in its place.

How to report

Email [email protected].

If you can, encrypt your message with our PGP key. Download the key

Or use the contact form and pick the “Security report” topic.

What to include

  • The affected URL or system.
  • A short description of the issue.
  • Steps to reproduce it, so we can see it too.
  • The impact: what an attacker could do with it.
  • A proof of concept, if you have one. Keep it harmless.

What is in scope

We want to hear about issues on:

  • uptools.io and all of its subdomains.
  • Client sites we run whose security.txt points here.

Not sure whether a site is ours? Check its /.well-known/security.txt. If it points here, you are in the right place.

What we do not treat as a vulnerability

These can be useful hints, but on their own they are not a risk. If you can actually exploit one, show us how.

  • Missing security headers without a concrete way to exploit them.
  • SPF, DKIM or DMARC suggestions.
  • Clickjacking on pages with no sensitive action.
  • A software version number on its own.
  • Unverified output from automated scanners.
  • Missing rate limiting on endpoints that are not sensitive.
  • Self-XSS that only works in your own browser.
  • CSRF on logout.

Please do not

Your testing should never harm us or our clients.

  • Run denial of service (DoS) or load tests.
  • Use social engineering on our team or our clients.
  • Try to get physical access to offices, servers or devices.
  • View, change or delete other users’ data. If you get access by accident, stop and tell us.
  • Send spam.
  • Run automated mass scans.

What we promise

  1. 1

    Within one business day

    we confirm that your report has arrived.

  2. 2

    Within 10 business days

    you get a first real assessment: how serious it is and what we plan to do.

  3. 3

    Along the way

    we keep you posted on the fix and tell you when it is done.

  4. 4

    Disclosure, together

    Please keep it private until it is fixed. Our default deadline is 90 days.

Research in good faith

If you follow this policy and stay within the limits above on systems we own or are authorized to test, we consider your research authorized. We will not report you or bring a civil claim because of that research, unless the law requires us to. This does not bind the authorities or anyone else. Client systems are covered only where the client has authorized us to permit testing.

Rewards

We do not pay bounties. If you like, we will thank you publicly, by name or alias.

If you ask for payment before sharing the details, we cannot work with you.

For machines, too

The same, in short, in the standard security.txt format. This is what security tools read.

Open the file

/.well-known/security.txt
Contact: mailto:[email protected]Contact: https://uptools.io/hu/contact/?topic=securityExpires: 2027-10-05T00:00:00.000ZEncryption: https://uptools.io/.well-known/pgp-key.txtPreferred-Languages: hu, enPolicy: https://uptools.io/security/Canonical: https://uptools.io/.well-known/security.txt