Responsible Disclosure Policy
Last Updated: 7 May 2026
Subnet Calc Limited takes the security of the Subnet Calc service seriously. We welcome and appreciate reports of security vulnerabilities from researchers, customers, and the wider community.
Scope
This policy covers vulnerabilities in:
- The Subnet Calc web application at
www.subnetcalc.comand its regional subdomains (northeurope.subnetcalc.com,eastus.subnetcalc.com,australiaeast.subnetcalc.com) - The Subnet Calc backend API at
global.subnetcalc.com
Out of Scope
The following are not in scope:
- Third-party services (Stripe, SendGrid, Microsoft, Google, Apple, CookieBot) — report issues to those providers directly
- Social engineering, phishing, or physical attacks
- Denial-of-service (DoS/DDoS) attacks
- Automated scanning that degrades service availability
- Vulnerabilities in software or infrastructure not operated by us
How to Report
Submit vulnerability reports via our support page. Select “Security Vulnerability” as the request type.
Please include:
- Description — what the vulnerability is and its potential impact
- Steps to reproduce — clear, step-by-step instructions to reproduce the issue
- Proof of concept — screenshots, logs, or code demonstrating the vulnerability (if applicable)
- Your contact information — so we can follow up with questions or updates
What to Expect
| Step | Timeframe |
|---|---|
| Acknowledgement | Within 2 business days |
| Initial assessment | Within 5 business days |
| Status update | Every 7 days until resolved |
| Resolution target | Within 30 days for critical/high severity; 90 days for medium/low |
We will keep you informed of our progress and notify you when the issue is resolved.
Safe Harbour
We will not take legal action against researchers who:
- Act in good faith and in accordance with this policy
- Avoid accessing, modifying, or deleting data belonging to other users
- Do not exploit the vulnerability beyond what is necessary to demonstrate it
- Do not publicly disclose the vulnerability before it has been resolved (or without our written agreement)
- Do not perform actions that could degrade the Service for other users (e.g., DoS, data destruction, spam)
Recognition
We appreciate responsible disclosure. With your permission, we may:
- Acknowledge your contribution on this page (if you wish to be credited)
- Provide a reference for your portfolio or CV
We do not currently operate a monetary bug bounty programme.
Guidelines
When researching vulnerabilities, please:
- Do use test accounts you control
- Do stop and report if you accidentally access another user's data
- Do not access, modify, or delete data belonging to other users
- Do not perform destructive actions
- Do not use automated tools that generate significant traffic
- Do not publicly disclose vulnerabilities before they are resolved
Contact
Security Reports:
Submit via our support page — select “Security Vulnerability” as the request type.
Security operations and incident response are managed by Inflecto Systems Ltd on behalf of Subnet Calc Limited.