Skip to content
Tulmira

Legal

Security & Vulnerability Disclosure

Last updated 7 October 2026

We welcome reports from security researchers. If you believe you have found a vulnerability in tulmira.com or one of our products, please tell us privately so we can fix it before it is disclosed.

First response
Within 3 working days
Machine-readable
/.well-known/security.txt

In scope

tulmira.com and its subdomains, and the EvalCV, PulsVault, Proxar and Docs Flowy products and APIs operated by Tulmira Ltd.

How to report

Email [email protected] with a description of the issue, the steps to reproduce it and its likely impact. Screenshots or a short proof of concept help us fix it faster.

Please do not

Access, change or delete data that is not yours, degrade the service for other users, run denial-of-service or social-engineering tests, or publish details before we have released a fix.

Our commitment

We will acknowledge your report, keep you updated while we investigate and tell you when it is fixed. We will not take legal action against research carried out in good faith within this policy, and we are happy to credit you once the issue is resolved.

Questions about this document? Email [email protected] or write to Tulmira Ltd, 128 City Road, London EC1V 2NX.