Trust · Trust disclosure
Report a potential security issue without increasing the risk to users or systems.
This policy explains what to include in a report, where to send it, which testing is not authorised, how Semantec SEO handles reports, and how disclosure should be coordinated.
Verified facts and boundaries.
These fields identify the entity, product, document, or operational boundary without turning related parties into the same entity.
Use the published report route.
Send a potential vulnerability or security concern to privacy@semantecseo.com with the subject 'Security report'. Product access issues that do not involve a security risk may use support@semantecseo.com.
A report should identify the affected URL or system, date and time, environment, observed behaviour, possible impact, and the minimum steps required to reproduce the issue safely.
Do not test beyond the minimum needed to report.
- Do not access, modify, copy, delete, or expose another person's data
- Do not use social engineering, phishing, credential attacks, or malware
- Do not perform denial-of-service, load, stress, or resource-exhaustion testing
- Do not attempt persistence, lateral movement, or privilege escalation beyond the observed issue
- Do not bypass payment, entitlement, rate, safety, or account controls
- Do not scan or test third-party systems without their written authorisation
- Do not publish a live exploit or unremediated vulnerability before coordination
This page is not blanket testing permission.
The policy invites good-faith reporting of issues encountered through ordinary use or minimal verification. It does not authorise intrusive testing, access to non-public systems, access to user data, or testing of OpenAI, Stripe, Authflow.ai, hosting, email, or other third-party infrastructure.
Obtain written permission before testing beyond the published boundary.
Protect the evidence.
Send only the information necessary to assess the issue. Mask personal data, credentials, tokens, payment information, and confidential material. Use a secure transfer route if Semantec SEO requests one.
Do not include proprietary third-party code or data that you are not authorised to share.
How reports are handled.
| Stage | Semantec SEO action | Reporter expectation |
|---|---|---|
| Acknowledgement | Confirm receipt and assign a record | Provide a reliable contact route |
| Triage | Confirm scope, severity, ownership, and affected provider | Answer proportionate clarification questions |
| Containment | Reduce immediate risk where possible | Do not continue testing without agreement |
| Remediation | Repair the controlled system or route the issue to the provider | Allow reasonable time based on risk and dependency |
| Verification | Check the fix and affected routes | Retest only within the agreed scope |
| Disclosure | Agree whether and when public acknowledgement is suitable | Do not publish before coordination |
External platform issues.
A concern that belongs to OpenAI, Stripe, Authflow.ai, a hosting provider, or another external service may need to be reported through that provider's security channel. Semantec SEO can route a report when it affects its own service, but it cannot promise control over the provider's investigation or timeline.
Recognition and bounty.
Semantec SEO does not promise a financial bounty, reward, public credit, or safe-harbour commitment beyond the written scope of this policy. Any recognition is discretionary and subject to privacy, legal, and operational considerations.
Check the controlling first-party and official sources.
These routes support the current public statement. External platform and legal sources remain subject to their own updates.
Semantec SEO Acceptable Use
Current first-party security-testing and misuse restrictions.
OpenAI usage policies
Official current platform safety requirements.
Semantec SEO contact route
Current support and privacy contact information.
Move to the page that owns the next question.
Each route has a separate job so company, product, trust, legal, and compliance information does not collapse into one promotional page.
Owned route
Security overview
Scope, provider boundary, account responsibility, and claims.
Open route →
Owned route
Privacy Policy
Personal-data handling and reporting contact.
Open route →
Owned route
Acceptable Use
Security testing, access, automation, and prohibited conduct.
Open route →
Owned route
Provider register
External platform owners and routes.
Open route →
Owned route
Contact
Support and privacy contact details.
Open route →
Owned route
Corrections Policy
Public correction and change-record process.
Open route →