Responsible Disclosure Policy
Version 1.0 · Last updated: 21 July 2026
Related: Terms · Acceptable Use · Trust Center
Security is a top priority. We welcome reports from independent security researchers who help us keep the SeedMatchGroup platform, our users and Third Parties safe.
1. How to report
Send reports to security@seedmatchgroup.com. Please include: a clear description of the issue, affected URL/endpoint, reproduction steps, proof-of-concept, potential impact and any recommended remediation. Do not publicly disclose the issue before we have had a reasonable opportunity to remediate.
2. In scope
- Vulnerabilities in
seedmatchgroup.comand its subdomains that materially affect confidentiality, integrity or availability. - Authentication, authorisation and access-control flaws.
- Injection, SSRF, RCE, IDOR, sensitive data exposure and business-logic flaws.
3. Out of scope
- Denial-of-service, volumetric, resource-exhaustion or brute-force testing.
- Physical, social-engineering, phishing or third-party service testing.
- Automated scanner output without demonstrable impact.
- Missing security headers with no exploitable impact.
- Third-party integrations (hosting, analytics, email) — report those to their respective providers.
4. Rules of engagement
- Do not access, modify, download, delete or exfiltrate data belonging to other users.
- Do not degrade, disrupt or damage the Platform.
- Use only your own test accounts.
- Comply with applicable law.
5. Safe harbour
Where research is conducted in good faith and within this policy, SeedMatchGroup will not pursue civil or criminal action, and will work with you to understand and resolve the issue. This safe harbour does not extend to activity that violates law, harms users or breaches this policy.
6. Acknowledgement
We appreciate responsible disclosure and, at our discretion, acknowledge researchers who report qualifying issues.
