curanta

Security · Last updated Jul 28, 2026

Responsible disclosure

If you've found something we should fix, we want to hear from you. Here's how to report it and what to expect back.

How to report

Email security@curanta.io with:

  • A short description of the issue and its potential impact.
  • Steps to reproduce, or a proof of concept.
  • Your name and how you'd like to be credited (or that you prefer to stay anonymous).

What we'll do

  • Acknowledge within 3 business days.
  • Triage and share a severity assessment within 7 business days.
  • Fix critical issues as fast as we responsibly can; keep you updated as we work.
  • Credit you publicly once the fix is out, if you'd like.

Please don't

  • Access or modify other users' data.
  • Run automated scanners that generate significant load.
  • Exfiltrate more than the minimum needed to prove the issue.
  • Publicly disclose the issue before we've had a reasonable window to fix it.

Reports made in good faith and following this policy won't lead to legal action from us.

Out of scope

  • Reports generated only by automated tooling with no proof of impact.
  • Rate limiting on public marketing endpoints.
  • Missing headers with no exploit chain.
  • Best-practice suggestions without a demonstrated vulnerability.