Security

Found a vulnerability? Tell us.

We hold our own systems to the standards we recommend to clients. If you find a weakness, we want to hear about it.

How to report

Email security@casorizon.com with:

  • a description of the issue and where it is,
  • steps to reproduce it, and any proof-of-concept,
  • the impact you believe it has,
  • how you would like to be credited, if at all.

Please do not include personal data you may have accessed. If you need to send sensitive detail, ask us for an encryption key first.

Scope

In scope: casorizon.com and its subdomains, and email sent from them.

Out of scope:

  • denial-of-service testing, load testing or anything that degrades service,
  • social engineering of staff or contractors, and physical testing,
  • third-party services we use, unless the issue is in how we configured them,
  • reports from automated scanners without a demonstrated impact.

What we commit to

StageTarget
Acknowledge your reportWithin 3 working days
Initial assessmentWithin 10 working days
Updates while we fix itAt least every 30 days
Coordinated disclosureAgreed with you, normally within 90 days

Safe harbour

If you act in good faith, stay within the scope above, avoid privacy violations and service disruption, and give us reasonable time to fix the issue before disclosing it, we will not pursue or support legal action against you for your research. If in doubt about whether an action is acceptable, ask us first.

Rewards

We do not currently run a paid bug bounty. With your permission, we are glad to acknowledge your help publicly.