Responsible disclosure
Report suspected security vulnerabilities privately so they can be investigated and fixed without exposing customers or the service to unnecessary risk.
Contact
Send security reports to support@urdatlas.com with the subject line Security report. A dedicated security mailbox may replace this address later; this page is the canonical current contact.
Include
Describe the affected URL or component, reproduction steps, expected versus observed behavior, impact, and any non-sensitive evidence needed to reproduce the issue. Include your contact details if you want follow-up.
Safe testing boundary
Do not access or alter another customer's data, do not perform denial-of-service or high-volume testing, do not use social engineering, do not persist after obtaining sufficient proof, and do not publish sensitive details before Urd Atlas has had a reasonable opportunity to investigate and remediate.
Response target
Urd Atlas aims to acknowledge a credible security report within 3 business days and will provide follow-up based on severity and reproducibility. This is a response target rather than a contractual SLA.
Good-faith research
Good-faith research that stays within the boundaries above and is reported privately will not be treated as an attempt to bypass normal access controls solely because the researcher identified a vulnerability. This statement does not authorize illegal activity or testing against third-party infrastructure outside Urd Atlas' control.
