Responsible Disclosure Policy
How to report a vulnerability to us, and what we promise in return.
- Version
- 1.0
- Effective
- 26 July 2026
- Applies to
- Drentova Group Ltd
- History
- 1 version
Scope
This policy covers https://drentova.com and any service operated by Drentova Group Ltd. It does not cover third-party services we use — report those to their owners.
What we ask
- Report to [email protected] before disclosing anywhere else, and give us reasonable time to fix it.
- Give us enough detail to reproduce the issue.
- Do not access, modify or delete data that is not yours, and stop as soon as you have confirmed a vulnerability exists.
- Do not degrade the service — no denial of service, no automated scanning that generates significant load, no social engineering of our staff or customers.
What we promise
- We acknowledge within 3 working days and tell you our assessment within 10.
- We keep you updated until it is resolved, and tell you when it is.
- We will not pursue or support legal action against anyone acting in good faith under this policy.
- We will credit you publicly if you would like us to.
We do not currently run a paid bug bounty. We will say so here if that changes rather than leaving it ambiguous.
How to contact us
- Security reports
- [email protected]
Change log
- v1.0 · 26 July 2026First published version.