Security
First written: 5 July 2026 · Last updated: 10 October 2026
If you find a security problem in anything we have built, we want to hear about it.
The short version
- Report problems to security@jointhinkspark.com.
- We acknowledge reports within 5 working days.
- Good-faith research that follows this policy is welcome.
- Never access, change or delete other people's data.
What this covers
This website (jointhinkspark.com) and the tools the lab releases. Systems run by other organisations, such as our hosting provider or the platforms our tools work with, are not ours to authorise testing on. Please report problems with those to their owners.
How to report
Email security@jointhinkspark.com. These details help us act quickly:
- where the problem is;
- what someone could do with it;
- the steps to reproduce it;
- any proof of concept.
Anonymous reports are welcome. Please do not include other people's personal data in your report.
While you research, please
- tell us as soon as you find a problem;
- test only with your own accounts and data, and never access, change or delete anyone else's;
- stop and tell us straight away if you come across personal data;
- do not run denial-of-service tests, social engineering such as phishing our members, or physical tests;
- give us reasonable time to fix the problem before you talk about it publicly.
Our promise to you
If you research in good faith and follow this policy, we will treat your research as authorised, work with you to understand and fix the problem, and not take or recommend legal action against you over it. We can only make this promise for systems we own.
What to expect
We will acknowledge your report within 5 working days, keep you updated while we work on a fix, and, if you would like, credit you once it is fixed.
security.txt
Our contact details are also published in a security.txt file, the standard place security researchers look for them (RFC 9116).
The structure of this policy is adapted from the vulnerability disclosure policy template published by the US Cybersecurity and Infrastructure Security Agency (CISA).