Security
Security Reporting Policy
We take the security of our systems, and of the people who use them, seriously. If you believe you have found a security vulnerability in Spectre Assure, or in any other website, product or service operated by 0x6C Limited, we want to hear about it, and we appreciate the time and effort of the researchers who help us stay secure.
Reporting a vulnerability
Please email your report to security@spectreassure.com. Include enough detail for us to reproduce and understand the issue, such as:
- the website, service, or URL affected
- a description of the vulnerability and its potential impact
- clear, step-by-step instructions to reproduce it
- any proof-of-concept code, screenshots, or logs that help
If you would like to encrypt your report, contact us first and we will provide a key.
What to expect
We will acknowledge your report within five business days. We will keep you informed as we investigate, work to validate and fix confirmed issues in good time based on their severity, and let you know when the issue is resolved. We are a small team, so we appreciate your patience.
Guidelines
We ask that you:
- give us a reasonable opportunity to fix an issue before disclosing it publicly
- only interact with accounts and data that belong to you, or that you have explicit permission to test
- avoid actions that could harm the service or its users, such as denial-of-service testing, spamming, or degrading performance
- do not access, modify, or delete data that is not yours, and stop and report immediately if you encounter personal data that is not your own
Safe harbour
If you make a good-faith effort to follow this policy, we will treat your research as authorised, we will work with you to understand and resolve the issue quickly, and we will not pursue or support legal action against you in relation to it. If a third party brings legal action against you, we will make it known that you acted in accordance with this policy.
Out of scope
The following are generally not considered security vulnerabilities under this policy:
- reports from automated scanners without a demonstrated, exploitable impact
- volumetric denial-of-service or resource-exhaustion attacks
- social engineering of our staff, users, or suppliers
- missing security headers or best-practice suggestions with no direct security impact
- spam, or issues that require a compromised device or physical access to exploit
Recognition
We are a small company, so we do not run a paid bug bounty programme and cannot offer a financial reward for security findings. We are, however, genuinely grateful to everyone who reports issues responsibly, and with your permission we are happy to acknowledge your contribution once an issue has been resolved.
Last updated: 22 July 2026.