We welcome reports from security researchers. If you believe you have found a vulnerability in tulmira.com or one of our products, please tell us privately so we can fix it before it is disclosed.
- Report to
- [email protected]
- First response
- Within 3 working days
- Machine-readable
- /.well-known/security.txt
In scope
tulmira.com and its subdomains, and the EvalCV, PulsVault, Proxar and Docs Flowy products and APIs operated by Tulmira Ltd.
How to report
Email [email protected] with a description of the issue, the steps to reproduce it and its likely impact. Screenshots or a short proof of concept help us fix it faster.
Please do not
Access, change or delete data that is not yours, degrade the service for other users, run denial-of-service or social-engineering tests, or publish details before we have released a fix.
Our commitment
We will acknowledge your report, keep you updated while we investigate and tell you when it is fixed. We will not take legal action against research carried out in good faith within this policy, and we are happy to credit you once the issue is resolved.
Questions about this document? Email [email protected] or write to Tulmira Ltd, 128 City Road, London EC1V 2NX.