1. Scope
This policy covers security issues that directly affect the public atsrs.com website, authenticated ATSRS application, ATSRS-controlled sharing flows or ATSRS-controlled server functions.
Third-party identity, hosting, database, email, messaging or AI providers are governed by their own reporting programmes unless the issue is caused by ATSRS configuration or integration code.
2. What a useful report includes
- the affected page, feature or endpoint;
- a clear description of the expected and observed behaviour;
- minimal, repeatable steps using your own account and data;
- the potential impact and any conditions required;
- redacted screenshots or proof of concept where helpful; and
- a safe way to contact you for clarification.
Do not send passwords, access tokens, private keys, one-time codes or unredacted personal documents.
3. Responsible testing rules
- Use accounts and records you control or have explicit permission to test.
- Stop immediately if you encounter another person’s data and report only the minimum evidence needed.
- Do not modify, delete, retain or publicly disclose data that is not yours.
- Do not degrade availability, send spam, bypass rate limits at scale or create unnecessary production load.
- Do not use social engineering, phishing, physical intrusion or threats against users or staff.
4. Reports that normally need more evidence
Automated scanner output without a demonstrated impact, version banners, missing headers without an exploitable path, self-XSS, clickjacking on non-sensitive public pages and theoretical rate-limit observations may not be actionable on their own.
Availability testing, brute-force testing and testing against real-user data are not permitted.
5. What happens after a report
ATSRS will review reports according to likely impact, reproducibility and affected data. We may request clarification, contain the issue, prepare a fix and confirm when disclosure is appropriate.
6. Report privately
Use the existing ATSRS contact address with the subject “ATSRS Security Report”. Keep personal data redacted.
Privacy or account-deletion requests should use the separate Data Rights process.