Protecting our customers' data is our top priority. Security isn't an afterthought — it's built into our architecture, operations, and development process. If you find a vulnerability, help us fix it quickly.
This covers anything that could compromise user data or impact the service, including phishing attempts targeting Startup Business Cockpit or our users. The sooner we know, the faster we can act.
We will not take legal action against anyone who responsibly reports vulnerabilities. As long as you act in good faith, don't access other people's data, and give us time to fix the issue, you're safe.
We acknowledge receipt of your report within 48 hours and keep you informed about progress. Every report is treated confidentially and stored only as long as necessary for resolution or as required by law.
We do not operate a bug bounty program and do not pay rewards for reports. However, we appreciate every responsible disclosure and handle all reports carefully.
Our disclosure policy covers:
Third-party services (e.g. hosting providers) are not in scope. If you're unsure, just ask.
To help us understand the issue quickly, please include:
E-Mail: security@on-promise.cloud
Security.txt: security.txt