Skip to content

Security.

We build and secure systems for a living, so we take reports about our own seriously. If you've found a vulnerability in this site or anything we run, here's how to tell us and what happens next.

Reporting a vulnerability

Email security@venon.ie. We read it directly — it doesn't go through a ticket queue or a third party.

Please include:

  • What you found and where — a URL, an endpoint, or a specific page
  • How to reproduce it, in enough detail that we can see it ourselves
  • What an attacker could do with it
  • Any screenshots, request logs or proof-of-concept code

If you'd like to encrypt your report, say so and we'll arrange a key.

What happens next

We're a two-person studio, so these are commitments we can actually keep rather than enterprise-sounding numbers.

  • Within 2 working days — we acknowledge your report and tell you who's handling it
  • Within 5 working days — we come back with our assessment: whether we've reproduced it, how serious we think it is, and roughly when we expect to have it fixed
  • After the fix — we confirm it's closed and, if you'd like, credit you publicly

If something is critical and being actively exploited, we'll drop everything and keep you updated as we go.

Scope

In scope

  • venon.ie and any subdomain
  • The infrastructure this site runs on
  • Anything else we publicly say we operate

Out of scope

  • Our clients' systems. We don't own them and can't authorise testing on them. If you've found something in a site we built, tell us and we'll pass it to the client — don't test further.
  • Third-party services we use but don't control — Microsoft 365, Hostinger, Cloudflare. Report those to the provider.
  • Findings from automated scanners with no demonstrated impact
  • Missing security headers or best-practice recommendations with no exploitable consequence. Tell us anyway if you like, but they aren't vulnerabilities.
  • Social engineering of us, our clients or our suppliers
  • Physical access

Rules

While testing:

  • Don't run denial-of-service or load tests. Our hosting is shared infrastructure and you'd affect other people.
  • Don't access, modify or download data that isn't yours. If you find a way to reach someone else's data, stop, note how far you got, and tell us — you don't need to prove it by taking the data.
  • Don't leave anything behind. No persistent access, no accounts, no files.
  • Give us reasonable time to fix it before going public. We'd suggest 90 days, and we'll usually be much quicker.

Safe harbour

If you follow the rules above and report to us in good faith, we won't pursue legal action against you, and we'll say so if anyone else asks.

This doesn't cover testing that goes beyond what's described here, and it can't bind third parties — your hosting provider or ours may have their own terms.

We can't pay

We don't run a bug bounty. We're a new two-person studio and we're not in a position to offer money.

What we can offer: a fast, honest response from the people who actually own the system, and public credit if you want it. If that's not worth your time, we understand.

Machine-readable

Our security.txt is at /.well-known/security.txt, per RFC 9116.