ATSRSBack to product overview
SECURITY

Report a security issue responsibly.

Private, clear reports help ATSRS investigate potential vulnerabilities while protecting users and production data.

Last reviewed: 10 August 2026Reward programme: None at this stage
Report privatelyDo not publish a suspected vulnerability before ATSRS has had a reasonable opportunity to investigate.
Use minimum evidenceShow the issue without accessing, changing or downloading information that is not yours.
Avoid disruptionDo not run denial-of-service, brute-force or high-volume automated tests.
POLICY
1. Scope2. What to include3. Testing rules4. Out of scope5. What happens next6. Contact

1. Scope

This policy covers security issues that directly affect the public atsrs.com website, authenticated ATSRS application, ATSRS-controlled sharing flows or ATSRS-controlled server functions.

Third-party identity, hosting, database, email, messaging or AI providers are governed by their own reporting programmes unless the issue is caused by ATSRS configuration or integration code.

2. What a useful report includes

  • the affected page, feature or endpoint;
  • a clear description of the expected and observed behaviour;
  • minimal, repeatable steps using your own account and data;
  • the potential impact and any conditions required;
  • redacted screenshots or proof of concept where helpful; and
  • a safe way to contact you for clarification.

Do not send passwords, access tokens, private keys, one-time codes or unredacted personal documents.

3. Responsible testing rules

  • Use accounts and records you control or have explicit permission to test.
  • Stop immediately if you encounter another person’s data and report only the minimum evidence needed.
  • Do not modify, delete, retain or publicly disclose data that is not yours.
  • Do not degrade availability, send spam, bypass rate limits at scale or create unnecessary production load.
  • Do not use social engineering, phishing, physical intrusion or threats against users or staff.

4. Reports that normally need more evidence

Automated scanner output without a demonstrated impact, version banners, missing headers without an exploitable path, self-XSS, clickjacking on non-sensitive public pages and theoretical rate-limit observations may not be actionable on their own.

Availability testing, brute-force testing and testing against real-user data are not permitted.

5. What happens after a report

ATSRS will review reports according to likely impact, reproducibility and affected data. We may request clarification, contain the issue, prepare a fix and confirm when disclosure is appropriate.

Current programme limits: ATSRS does not currently promise a fixed response time, monetary bounty, public recognition or legal safe-harbour agreement. Responsible, good-faith reports are nevertheless welcomed and will be handled as resources permit.

6. Report privately

ATSRS Security Report

Use the existing ATSRS contact address with the subject “ATSRS Security Report”. Keep personal data redacted.

Start security email

Privacy or account-deletion requests should use the separate Data Rights process.

© 2026 ATSRSData Protection & GDPRTerms of UsePrivacy NoticeData RightsReport a Security Issue