Skip to main content
CSTSetup

Security Policy

Current as of September 2, 2026

On this page
  1. The good faith commitment
  2. How to submit a report
  3. What we promise to do
  4. Out of scope, and strictly prohibited
  5. Agreement
  6. Acknowledgements
  7. Questions

We appreciate the part security researchers play in keeping our users safe. If you find a vulnerability in any of our systems, please tell us. This page explains how to report it and what you can expect from us in return.

The good faith commitment

We will work with you in good faith and will not pursue legal action against you, provided your testing stays inside the rules below:

  • You do not compromise user data or company confidentiality.
  • You do not disrupt or degrade our services.
  • You keep strictly to the out of scope list further down this page.

How to submit a report

Email [email protected] with the subject line starting SECURITY so it reaches the right person quickly.

Please include enough detail for us to reproduce and confirm the finding. Screenshots and step by step instructions are always welcome. Tell us the date and time you tested and the account you tested with, so we can match your work against our own logs.

If you would rather send the details encrypted, email us first and we will arrange a channel with you.

What we promise to do

We are a small operation, but we commit to answering properly:

  • Acknowledgement. We will confirm we have your report within two business days.
  • Validation. We will work to reproduce and confirm the finding as quickly as we can, and we will tell you either way.
  • Credit. We are glad to thank you publicly in the acknowledgements at the bottom of this page for anything that leads to a real security fix, if you would like us to.

We do not currently run a paid bug bounty. We will say so up front rather than let anybody spend their time expecting one.

Out of scope, and strictly prohibited

Anything that disrupts the service or touches somebody else's data is a violation of this policy, whatever the intent behind it. Please do not:

  • Test destructively or at volume. No denial of service, no distributed denial of service, and no automated high volume scanning that degrades performance for real users.
  • Engineer people. No phishing or other deception aimed at our team, our partners or our users.
  • Reach for real data. Do not attempt to access, change or delete any user or company data. Use your own test accounts and stay inside them.
  • Test our physical premises. We do not have any, but it is worth stating.
  • Test other people's services. Anything not operated directly by cstsetup.com is out of scope, including our hosting, payment and email providers, each of whom runs their own disclosure programme.

Agreement

By submitting a report to us you confirm that you have read this policy and will keep to it.

Acknowledgements

Our thanks to the researchers who have followed this policy and helped keep CSTSetup secure:

  • Kunal Mhaske, for reported UI and UX security improvements (2026).

Questions

Email [email protected]. See also our Privacy Policy and our Terms of Service.