Legal
Responsible Disclosure
Last updated: 2026-07-15
CloudGenie Ltd (Durham, United Kingdom) welcomes reports from security researchers. If you believe you've found a vulnerability in CloudGenie, please tell us — we commit to working with you promptly and in good faith.
How to report
- Email security@cloudgenie.co with a description, reproduction steps and impact assessment
- Machine-readable details:
/.well-known/security.txton any CloudGenie domain - We acknowledge reports within 1 working day and aim to provide a remediation timeline within 5 working days
Scope
- www.cloudgenie.co, id.cloudgenie.co, finops.cloudgenie.co, studio.cloudgenie.co, app.cloudgenie.co
- The CloudGenie CLI and published APIs
Out of scope
- Denial-of-service or volumetric testing
- Social engineering, phishing of staff or customers, physical attacks
- Automated scanning that degrades service for others
- Issues in third-party services we use (report to the vendor)
- Reports based solely on version banners without a demonstrated vulnerability
Safe harbour
We will not initiate legal action against researchers who: act in good faith within this policy; avoid privacy violations, data destruction and service degradation; use only accounts they own or have explicit permission to test with; and give us reasonable time to remediate before public disclosure. Never access another tenant's data — if you encounter it accidentally, stop immediately and report.
Recognition
We do not currently operate a paid bug bounty. With your permission, we credit meaningful reports on this page once fixed.