Security
Found something? Tell us.
If you have found a vulnerability in a Threatsys property, we want to hear from you, and we will treat you well for telling us.
Safe harbour
If you act in good faith under this policy we will not pursue legal action, and we will work with you to understand and fix the issue quickly. Our own team has 150+ Hall of Fame entries; we know which side of this we are on.
In scope
- threatsys.ai and its subdomains
- threatsysone.com and the product consoles
- Our public API endpoints
Please do not
- Access, modify or destroy data that is not yours
- Run automated scanning that degrades service for others
- Perform social engineering against our staff or clients
- Publish before we have had a reasonable window to fix
What happens next
- Acknowledgement within two working days
- Triage and severity assessment within five working days
- Regular updates until resolution
- Public credit if you want it
Not sure where to start?
Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.












