Security Policy

Steersman welcomes good-faith reports of suspected security vulnerabilities in software developed by Steersman or in services operated by Steersman.

Please report security issues to security@steersman.works.

Reporting a Vulnerability

Please include enough information for us to understand and reproduce the issue, including the affected software or service, reproduction steps, potential impact, and relevant technical details.

Do not include credentials, customer data, or other sensitive information in your report unless specifically requested by Steersman. If you inadvertently encounter such information, stop testing and notify us.

Responsible Disclosure

This policy does not authorize access to systems or data you are not otherwise authorized to access, and does not authorize testing of customer or third-party systems.

Please do not disrupt services, degrade availability, modify or exfiltrate data, use social engineering, or continue testing beyond what is reasonably necessary to demonstrate a suspected vulnerability.

We ask that you give Steersman a reasonable opportunity to investigate and address a reported vulnerability before publicly disclosing it.

Our Response

Steersman reviews reported vulnerabilities, investigates credible reports, and addresses validated issues based on severity, potential impact, and relevant dependencies.

Issues originating in third-party software may be referred to the applicable software provider or addressed through available updates or mitigations.

No Bug Bounty

Steersman does not currently operate a paid bug bounty program. Submission of a vulnerability report does not create an entitlement to payment or other compensation.

For additional information about our security and data-handling practices, see our Data Handling and Privacy Policy.