SeraCase Trust Center
Contact the security team
Responsible disclosure, vulnerability reporting, and response expectations.
Responsible disclosure
Please report security issues privately. Give us reasonable time to investigate and remediate before public disclosure. Do not access other users’ data, disrupt service, or exfiltrate materials beyond what is needed to demonstrate the issue.
What to include
- Affected URL or API route
- Steps to reproduce
- Impact assessment (confidentiality, integrity, availability)
- Your contact details for follow-up
PGP key
PGP encryption for vulnerability reports is optional. Placeholder key ID: [PGP KEY PENDING]. Request the current public key by email if required by your firm’s process.
Response expectations
- Acknowledgement target: within 3 business days
- Initial severity triage shortly thereafter
- Remediation timeline depends on severity and complexity