How to report
Email security@casorizon.com with:
- a description of the issue and where it is,
- steps to reproduce it, and any proof-of-concept,
- the impact you believe it has,
- how you would like to be credited, if at all.
Please do not include personal data you may have accessed. If you need to send sensitive detail, ask us for an encryption key first.
Scope
In scope: casorizon.com and its subdomains, and email sent from them.
Out of scope:
- denial-of-service testing, load testing or anything that degrades service,
- social engineering of staff or contractors, and physical testing,
- third-party services we use, unless the issue is in how we configured them,
- reports from automated scanners without a demonstrated impact.
What we commit to
| Stage | Target |
|---|---|
| Acknowledge your report | Within 3 working days |
| Initial assessment | Within 10 working days |
| Updates while we fix it | At least every 30 days |
| Coordinated disclosure | Agreed with you, normally within 90 days |
Safe harbour
If you act in good faith, stay within the scope above, avoid privacy violations and service disruption, and give us reasonable time to fix the issue before disclosing it, we will not pursue or support legal action against you for your research. If in doubt about whether an action is acceptable, ask us first.
Rewards
We do not currently run a paid bug bounty. With your permission, we are glad to acknowledge your help publicly.