We are a security firm. We take vulnerability reports seriously, respond promptly, and protect researchers who act in good faith. This policy describes how to report issues and what to expect from us.
Our commitment to security researchers
ACE MATES operates a responsible disclosure policy based on coordinated disclosure principles. We will work with you to understand and resolve security issues quickly, and we will not pursue legal action against researchers who act in good faith and comply with this policy.
Safe harbour statement: If you discover a vulnerability in our systems and report it to us in good faith following this policy, ACE MATES will not pursue civil or criminal legal action against you for that discovery. We treat good-faith security research as a valuable contribution and will work with you constructively.
Response SLA
Initial acknowledgement
24 hours
We will confirm receipt of your report within 24 business hours
Triage and severity assessment
5 business days
We will assess severity and confirm the finding is reproducible
Critical / high severity fix
30 days
We aim to resolve critical and high severity findings within 30 days
Medium / low severity fix
90 days
Medium and low severity issues are resolved within 90 days
We will keep you informed of progress throughout the remediation period. If a finding requires more time to resolve, we will agree an extension with you before the deadline.
Scope
In scope
acetrust.eu and all subdomains
acemates.org and all subdomains
acemates.se and all subdomains
Any ACE MATES-operated web application, API, or service
Infrastructure directly operated by ACE MATES
Out of scope
Third-party services we use but do not operate (Google Workspace, AWS, etc.)
Findings from automated scanners without manual validation
Denial of service (DoS/DDoS) attacks or testing
Social engineering of ACE MATES staff or clients
Physical security testing
Findings already reported by another researcher
Clickjacking on pages with no sensitive actions
Missing security headers without demonstrated impact
What we ask of researchers
Do not access or modify data belonging to other users without explicit permission
Do not perform testing that disrupts production systems or degrades service for others
Do not disclose the vulnerability publicly until we have resolved it and agreed on disclosure timing
Provide sufficient detail to reproduce the finding — including steps, screenshots, and proof of concept where safe to do so
Allow us reasonable time to remediate before publishing — we will commit to a specific timeline
Test only against your own accounts or test environments we have explicitly provided
How to report
Send your vulnerability report to our security team. Please include: a clear description of the vulnerability, steps to reproduce, the potential impact, and any proof-of-concept you can safely share.
Email
security@acetrust.eu — monitored 24/7 for critical issues, business hours for others.
Encrypted submission (PGP)
For sensitive findings, please encrypt your report using our PGP public key:
-----BEGIN PGP PUBLIC KEY BLOCK-----
Comment: ACE MATES Security Team · security@acetrust.eu
[Replace this block with your actual PGP public key.
Generate one at: https://keys.openpgp.org or using GPG:
gpg --gen-key
gpg --armor --export security@acetrust.eu]
-----END PGP PUBLIC KEY BLOCK-----
Key fingerprint: [Add your key fingerprint here]
Recognition
We do not currently offer a paid bug bounty programme. However, we do recognise researchers who responsibly disclose valid findings:
Public acknowledgement in our security hall of fame (with your permission)
A letter of recognition suitable for professional use
For critical findings, a complimentary service credit or consultation at our discretion
We evaluate each submission individually and are always open to discussing appropriate recognition for significant findings.
Legal
This policy is subject to Swedish law. ACE MATES AB reserves the right to update this policy at any time. Material changes will be communicated via a notice on this page. Last updated: June 2025.