← Back to Home

Vulnerability Disclosure Program

Guidelines for responsible security research and coordinated disclosure.

Overview

Tsenta takes the security of its products, services, and users seriously. We welcome reports from security researchers who identify potential vulnerabilities and disclose them to us responsibly and in good faith.

This policy explains how to report a vulnerability, what testing is permitted, and what you can expect from Tsenta after submitting a report.

How to Report a Vulnerability

Please send vulnerability reports to:

founders@tsenta.com

Your report should include, where applicable:

  • a clear description of the vulnerability;
  • the affected product, service, endpoint, or feature;
  • detailed and reproducible steps;
  • the potential security impact;
  • any prerequisites or required user interaction;
  • supporting evidence, such as screenshots, logs, request and response data, or a proof of concept; and
  • your name or preferred attribution, if you would like to be credited.

Please provide enough information for us to reproduce and validate the issue. Reports generated solely by automated tools, without demonstrated impact or manual verification, may not be accepted.

Scope

The following assets are in scope unless Tsenta provides written instructions stating otherwise:

  • the Tsenta browser extension;
  • tsenta.com and web services operated by Tsenta;
  • Tsenta-owned API endpoints;
  • authentication and authorisation controls;
  • access-control vulnerabilities;
  • unintended exposure of sensitive information; and
  • security flaws that could materially affect Tsenta users or systems.

Only systems and services owned or operated by Tsenta are covered by this policy.

Out of Scope

The following activities and report types are out of scope:

  • denial-of-service or distributed denial-of-service testing;
  • load testing or activity intended to degrade availability or performance;
  • social engineering, phishing, impersonation, or physical attacks;
  • testing of employees, contractors, customers, or other users;
  • vulnerabilities in third-party products, services, or dependencies that Tsenta does not control;
  • automated scanner results without a reproducible security impact;
  • spam, brute-force attacks, credential stuffing, or password spraying;
  • attempts to access, alter, download, retain, or delete another person’s data;
  • destructive testing;
  • persistence, lateral movement, or post-exploitation activity;
  • deployment of malware;
  • testing that could affect production data or service availability; and
  • any activity prohibited by applicable law.

If you are unsure whether testing is permitted, contact us before proceeding. Written authorisation from Tsenta may be required for testing outside the ordinary scope of this policy.

Responsible Research Requirements

To remain covered by this policy, you must:

  • act in good faith;
  • test only the minimum necessary to demonstrate the vulnerability;
  • avoid accessing or interacting with data belonging to other users;
  • stop testing immediately if you encounter personal data, confidential information, credentials, or evidence of unauthorised access;
  • avoid modifying, deleting, downloading, retaining, or disclosing data;
  • avoid disrupting, degrading, or impairing Tsenta’s systems or services;
  • not use a vulnerability for personal gain beyond any compensation offered under this program;
  • not threaten disclosure, regulatory complaints, media contact, or other action in connection with a demand for payment;
  • keep vulnerability details confidential while Tsenta investigates and remediates the issue;
  • provide reasonable time for investigation and remediation before any proposed disclosure; and
  • comply promptly with any instruction from Tsenta to stop or limit testing.

Submitting a report does not authorise continued testing. Tsenta may withdraw or restrict testing permission at any time.

Coordinated Disclosure

You must not publicly disclose a vulnerability or related technical information without first coordinating with Tsenta.

Before any proposed disclosure, please provide reasonable advance written notice of:

  • the intended publication date;
  • the information you intend to disclose; and
  • any proof-of-concept material you intend to publish.

Disclosure must not include personal data, credentials, confidential or proprietary information, or technical details that would create an unnecessary risk to users.

Tsenta may request additional time where remediation is complex, dependent on third parties, or requires a coordinated release.

What We Promise

If you submit a report in good faith and comply with this policy, Tsenta will:

  • acknowledge receipt of your report, normally within 48 hours;
  • review and assess the report;
  • notify you if the issue is accepted for further investigation;
  • keep you reasonably informed of material progress;
  • address validated vulnerabilities in accordance with our internal security and engineering processes;
  • notify you after the issue has been resolved, normally within 48 hours of confirming the resolution;
  • not pursue legal action against you in relation to research conducted in compliance with this policy;
  • not share your personal information with third parties without your permission, except where required by law, regulation, legal process, or a lawful request from an authority; and
  • provide public credit, where appropriate and where you request it.

Response and remediation times may vary depending on severity, complexity, affected systems, and operational requirements.

Safe Harbor

Tsenta will not initiate legal action against researchers for accidental, good-faith violations of this policy where the researcher:

  • promptly reports the issue;
  • avoids causing harm;
  • stops testing when requested;
  • does not misuse or disclose information obtained during testing; and
  • cooperates with Tsenta’s investigation and remediation process.

Safe harbor does not apply to conduct involving extortion, coercion, intentional disruption, data theft, privacy violations, unlawful access, destruction of data, denial-of-service activity, or continued testing after authorisation has been withdrawn.

This policy does not provide immunity from the actions of third parties or from obligations imposed by applicable law.

Compensation

Tsenta may, at its sole discretion, offer compensation for valid and previously unknown vulnerabilities.

Compensation is not guaranteed and will depend on factors including:

  • demonstrated security impact;
  • exploitability;
  • affected users and systems;
  • report quality and reproducibility;
  • whether the issue was previously known;
  • whether the issue is within scope; and
  • whether the researcher complied with this policy.

Submitting a report does not create a contractual entitlement to payment.

Tsenta does not make advance payments for undisclosed vulnerabilities and will not agree to compensation before a report has been sufficiently disclosed, reproduced, and validated.

Reports involving out-of-scope activity or testing conducted in breach of this policy are not eligible for compensation.

Eligibility

A report may be ineligible for acknowledgement, credit, or compensation where:

  • the issue is already known to Tsenta;
  • the report is incomplete or cannot be reproduced;
  • the claimed impact is not demonstrated;
  • the report concerns an out-of-scope asset or activity;
  • the issue has no meaningful security impact;
  • the report is based solely on automated scanning;
  • the researcher violated this policy;
  • the researcher continued testing after being instructed to stop; or
  • the researcher publicly disclosed the issue before completing coordinated disclosure.

Changes to This Policy

Tsenta may amend this policy at any time. The version in effect at the time testing is conducted will apply to that activity.

Questions about this policy or whether a proposed test is permitted should be sent to founders@tsenta.com before testing begins.