Case StudiesDocsPricingBlogContact
Log InGet started
Security

Responsible
Disclosure

Last Updated: July 19, 2026

We take security seriously and welcome reports from the security research community. This page describes how to report a vulnerability, what is in and out of scope, what to expect from us in response, and the safe-harbour commitments that apply to good-faith research.

1. How to Report

Email [email protected] with subject line [SECURITY] <short title>. Do not include live credentials, personal data, or an unredacted exploit in the first email. Ask for an encrypted channel and we will arrange one after acknowledging the report.

A good report includes:

Please do not file vulnerability reports through public channels (GitHub issues, X, LinkedIn) before we have had a chance to respond.

2. Scope

In scope:

Out of scope:

3. Response Targets

We are a small team in open beta — we will be honest about timing rather than promise enterprise SLAs we cannot meet. Our targets:

StageTarget
Acknowledgement of reportWithin 2 business days
Initial triage + severity assessmentWithin 5 business days
Critical-severity remediationBest-effort within 14 days; mitigation faster
High-severity remediationWithin 30 days
Medium / Low remediationBest-effort, no fixed timeline
Public credit (if requested)After fix is deployed and verified

4. Safe Harbour

Sentinel authorises good-faith security testing of the in-scope assets listed above, only within the limits of this policy. If you comply with those limits, Sentinel will:

"Good faith" means: making a sincere effort to avoid privacy violations, service degradation, and data destruction; stopping testing as soon as the vulnerability is established; not exfiltrating customer data beyond the minimum needed to demonstrate the issue; not using the access to pivot into other customer data or systems.

This policy cannot authorise testing of systems owned by customers or third parties and cannot bind law enforcement, prosecutors, regulators, vendors, or any other third party. It does not immunise conduct that is unlawful or outside this policy. If you are unsure whether a test is covered, contact us before proceeding.

5. What We Ask You Not to Do

6. Bug Bounty

We do not currently run a paid bug-bounty programme. We are happy to publicly credit researchers, send Sentinel-branded swag for substantial reports during beta, and open a discussion about a paid programme as we move toward general availability. If you are seeking a paid bounty up front, please mention this in your initial email so we can be transparent about expectations.

7. Other Trust & Compliance Signals

8. Researcher acknowledgments

We publish researcher names or handles here only with their permission after remediation. No public acknowledgments have been requested yet.

9. Contact

Sentinel Security

[email protected] · subject prefix [SECURITY]

Sentinel Edge Networks LTD is registered in England and Wales under company number 17150600. Registered office: 134a West Hendon Broadway, London, NW9 7AA, United Kingdom.

Machine-readable disclosure metadata at /.well-known/security.txt per RFC 9116.