Responsible Disclosure Policy
Last updated: 3 May 2026
Overview
We take security seriously. If you have discovered a vulnerability in ContechCost, we ask that you disclose it to us responsibly so we can address it before it is exploited. We will not take legal action against researchers who act in good faith under this policy.
How to Report
Email your findings to support@contechcost.com. Please include:
- A clear description of the vulnerability and its potential impact.
- Steps to reproduce, including any URLs, payloads, or screenshots.
- Your name or handle, if you would like credit.
Encrypt your report with our PGP key if the content is sensitive. We will reply with our key on request.
Our Commitments
- We will acknowledge receipt within 5 business days.
- We will investigate and keep you informed of our progress. We aim to resolve confirmed critical issues within 30 days.
- We will not pursue legal action against researchers who comply with this policy, provided they do not: access or modify customer data beyond what is needed to demonstrate the issue, disrupt production services, or disclose the vulnerability publicly before we have had a reasonable opportunity to fix it.
- We will credit researchers who report valid, previously-unknown vulnerabilities, if they wish to be named.
Scope
In scope:
- contechcost.com — the main application and all authenticated endpoints.
- Regional MCP servers (for example, au.contechcost.com/mcp) — the MCP endpoints used by AI clients.
- contechcost.com/api — all API routes.
Out of scope:
- Denial-of-service attacks.
- Automated scanning that degrades service for other users.
- Social engineering of ContechCost staff.
- Vulnerabilities in third-party services (Supabase, Cloudflare, Stripe) — report those directly to the relevant vendor.