Vulnerability Disclosure Policy
Last updated: 1 October 2026
If you've found a security vulnerability in Vyce, we want to hear about it.
How to report
Email security@vyce.io with:
- Where you found it, and how to reproduce it
- What an attacker could do with it
- Any supporting detail — screenshots, logs, proof of concept
What we'll do
- Acknowledge your report within five working days
- Keep you updated on our assessment and fix
- Tell you when it's resolved
- Credit you publicly if you'd like us to
What we ask
- Give us reasonable time to fix the issue before disclosing it publicly
- Don't access, modify or delete data that isn't yours
- Don't degrade our service, and don't run denial of service or automated scanning against production
- Don't use social engineering or physical attacks against our people or offices
Our commitment
If you follow this policy, act in good faith and report promptly, we won't pursue legal action against you.
Out of scope
Automated scanner output with no demonstrated impact, missing security headers with no exploitable consequence, and issues in third-party services we don't control.
Vyce Contractors Limited
Registered in England and Wales, company number 13370239
Registered office: 31 New Inn Yard, London EC2A 3EY
VAT registration number: 380910500
Vyce Contractors Limited licenses the Vyce platform and related intellectual property from Vyce Group Limited (company number 09875720).