Security · Legal

Responsible Disclosure

We are a security firm. We take vulnerability reports seriously, respond promptly, and protect researchers who act in good faith. This policy describes how to report issues and what to expect from us.

Our commitment to security researchers

ACE MATES operates a responsible disclosure policy based on coordinated disclosure principles. We will work with you to understand and resolve security issues quickly, and we will not pursue legal action against researchers who act in good faith and comply with this policy.

Safe harbour statement: If you discover a vulnerability in our systems and report it to us in good faith following this policy, ACE MATES will not pursue civil or criminal legal action against you for that discovery. We treat good-faith security research as a valuable contribution and will work with you constructively.

Response SLA

Initial acknowledgement
24 hours
We will confirm receipt of your report within 24 business hours
Triage and severity assessment
5 business days
We will assess severity and confirm the finding is reproducible
Critical / high severity fix
30 days
We aim to resolve critical and high severity findings within 30 days
Medium / low severity fix
90 days
Medium and low severity issues are resolved within 90 days

We will keep you informed of progress throughout the remediation period. If a finding requires more time to resolve, we will agree an extension with you before the deadline.

Scope

In scope
  • acetrust.eu and all subdomains
  • acemates.org and all subdomains
  • acemates.se and all subdomains
  • Any ACE MATES-operated web application, API, or service
  • Infrastructure directly operated by ACE MATES
Out of scope
  • Third-party services we use but do not operate (Google Workspace, AWS, etc.)
  • Findings from automated scanners without manual validation
  • Denial of service (DoS/DDoS) attacks or testing
  • Social engineering of ACE MATES staff or clients
  • Physical security testing
  • Findings already reported by another researcher
  • Clickjacking on pages with no sensitive actions
  • Missing security headers without demonstrated impact

What we ask of researchers

  1. Do not access or modify data belonging to other users without explicit permission
  2. Do not perform testing that disrupts production systems or degrades service for others
  3. Do not disclose the vulnerability publicly until we have resolved it and agreed on disclosure timing
  4. Provide sufficient detail to reproduce the finding — including steps, screenshots, and proof of concept where safe to do so
  5. Allow us reasonable time to remediate before publishing — we will commit to a specific timeline
  6. Test only against your own accounts or test environments we have explicitly provided

How to report

Send your vulnerability report to our security team. Please include: a clear description of the vulnerability, steps to reproduce, the potential impact, and any proof-of-concept you can safely share.

Email

security@acetrust.eu — monitored 24/7 for critical issues, business hours for others.

Encrypted submission (PGP)

For sensitive findings, please encrypt your report using our PGP public key:

-----BEGIN PGP PUBLIC KEY BLOCK----- Comment: ACE MATES Security Team · security@acetrust.eu [Replace this block with your actual PGP public key. Generate one at: https://keys.openpgp.org or using GPG: gpg --gen-key gpg --armor --export security@acetrust.eu] -----END PGP PUBLIC KEY BLOCK-----

Key fingerprint: [Add your key fingerprint here]

Recognition

We do not currently offer a paid bug bounty programme. However, we do recognise researchers who responsibly disclose valid findings:

  • Public acknowledgement in our security hall of fame (with your permission)
  • A letter of recognition suitable for professional use
  • For critical findings, a complimentary service credit or consultation at our discretion

We evaluate each submission individually and are always open to discussing appropriate recognition for significant findings.

Legal

This policy is subject to Swedish law. ACE MATES AB reserves the right to update this policy at any time. Material changes will be communicated via a notice on this page. Last updated: June 2025.

For questions about this policy, contact security@acetrust.eu.

Report a vulnerability
Security team contact

For all vulnerability reports. Monitored continuously for critical issues.

security@acetrust.eu
24h acknowledgement SLA 5-day triage SLA Safe harbour policy
Useful links