Skip to main content

    Vulnerability Disclosure Policy

    How to report a security vulnerability to us, and our commitment to researchers who report in good faith.

    Last updated01 July 2026
    Version1.0

    We take the security of our service seriously, and we value the work of the security research community. If you have discovered a security vulnerability in our service, this policy explains how to report it to us, what you can expect in return, and the conditions under which we will treat your research as authorised.

    On this page
    1. Our commitment
    2. Scope
    3. How to report
    4. What to expect from us
    5. Safe harbor
    6. Guidelines for researchers
    7. Out of scope
    8. Recognition
    9. Legal

    01 Our commitment

    Protecting our customers' data is a priority, and no system is perfect. We welcome reports of security issues and will work with you to understand and resolve them quickly. We commit to responding to good-faith reports, keeping you informed of our progress, and not pursuing legal action against researchers who follow this policy.

    ↑ Back to top

    02 Scope

    This policy applies to security vulnerabilities discovered in:

    • our website at outcome1.ai; and
    • our application at platform.outcome1.ai.

    If you are unsure whether something is in scope, contact us before testing and we will let you know.

    ↑ Back to top

    03 How to report

    Please send your report to security@outcome1.ai. To help us assess and reproduce the issue quickly, please include:

    • a description of the vulnerability and its potential impact;
    • clear steps to reproduce it, including any proof-of-concept;
    • the affected URL, system or component; and
    • any tools, configurations or accounts you used.

    Please report a vulnerability as soon as you can after discovering it, and give us a reasonable opportunity to address it before disclosing it to anyone else.

    ↑ Back to top

    04 What to expect from us

    When you report a vulnerability in line with this policy, we will:

    • acknowledge receipt of your report in good faith and as promptly as we reasonably can;
    • provide an initial assessment and keep you informed as we investigate;
    • work to remediate confirmed vulnerabilities on a best-effort basis, in a timeframe appropriate to their severity; and
    • let you know when the issue has been resolved.

    We do not commit to fixed response or resolution deadlines, but we treat security reports as a priority and will give yours prompt attention.

    ↑ Back to top

    05 Safe harbor

    We consider security research and vulnerability disclosure carried out in accordance with this policy to be authorised conduct. If you act in good faith and within this policy, we will not pursue or support legal action against you in relation to your research, and we will treat your activity as authorised under applicable computer-misuse and similar laws to the extent we are able.

    This protection applies only while you comply with this policy. It does not extend to actions that go beyond it, and it cannot waive the rights of third parties. If legal action is initiated by someone else against you for activity conducted in line with this policy, we will make clear that your conduct was authorised by us.

    ↑ Back to top

    06 Guidelines for researchers

    To stay within this policy, please:

    • act in good faith and avoid any privacy violations, disruption to others, or destruction of data;
    • only interact with accounts you own or have explicit permission to test;
    • access only the minimum amount of data needed to demonstrate the vulnerability, and never view, store, transfer or use anyone else's data;
    • stop testing and notify us immediately if you encounter personal data or sensitive information; and
    • keep the details of any vulnerability confidential until we have resolved it and agreed timing for disclosure with you.
    ↑ Back to top

    07 Out of scope

    The following are not authorised under this policy, and we ask that you do not attempt them:

    • denial-of-service attacks, or any testing that degrades or disrupts the service;
    • social engineering of our staff, customers or vendors, and physical attacks against our offices or people;
    • spam, or automated testing that generates excessive traffic;
    • accessing, modifying or deleting data that does not belong to you beyond what is strictly necessary to demonstrate an issue; and
    • vulnerabilities in third-party services or integrations that we do not control, which should be reported to the relevant provider.
    ↑ Back to top

    08 Recognition

    We are grateful to the researchers who help keep our service and our customers safe. With your permission, we are happy to acknowledge your contribution once an issue has been resolved.

    ↑ Back to top