Vulnerability Disclosure Policy

Effective 26 May 2026 · BakersGuild Ltd

We take security seriously. If you discover a vulnerability in Mail-Organiser, we want to hear from you. This policy explains how to report a vulnerability responsibly and what you can expect from us in return.

1. Our commitment to you

We will:

2. How to report

  1. Email your report to [email protected].
  2. Include a clear description of the vulnerability and its potential impact.
  3. Provide step-by-step reproduction instructions, including any tools used.
  4. Include screenshots, proof-of-concept code, or network traces where relevant.
  5. Tell us which systems or URLs are affected.

If the vulnerability is sensitive, you may encrypt your report using our PGP key (available on request).

3. Scope — in scope

4. Scope — out of scope

5. Good-faith rules

To qualify for safe harbour under this policy, you must:

6. No bug bounty

We do not currently operate a paid bug bounty programme, but we genuinely appreciate responsible disclosures and will acknowledge all valid reports publicly (with your permission).

Report a vulnerability

Encrypt sensitive reports on request. We respond within 3 business days.

Email [email protected]