Responsible Disclosure · Last updated 17 July 2026
We ask our clients to run a disclosure process. It would be poor form not to run one ourselves. If you’ve found a security issue in a system we operate, we want to hear about it, and we won’t pursue you for telling us in good faith.
Email security@invictuscybersecurity.tech. Ask for a PGP key if you’d rather encrypt the report and we’ll send one.
Useful things to include: what you found, where, how to reproduce it, and what an attacker could do with it. A rough note beats no note — don’t polish it, just send it.
In scope: invictuscybersecurity.tech and its subdomains.
Out of scope: our third-party providers — Webflow, Google, Proton, Calendly — who run their own disclosure programmes; please report to them directly. Also out of scope: any client system. We do not own them and cannot authorize testing against them. Testing a client environment because you found it through us is not covered by this policy and is not something we can protect you from.