← AuditSchedule

Reporting a vulnerability

Last reviewed 20 September 2026  ·  Node Logic, trading as AuditSchedule


If you have found a security problem in AuditSchedule, we want to hear about it. This page says how to tell us, what we will do about it, what we ask of you in return, and what protection you have for looking in the first place.

How to report

Email security@auditschedule.com. Tell us what you found, how to reproduce it, and what it would let someone do. A short description with exact steps is worth more to us than a long report without them.

We do not publish a PGP key, so treat the email as unencrypted and send us only what is needed to demonstrate the problem.

The same contact details are published in machine-readable form at /.well-known/security.txt.

What we commit to

We will not give you a fix date when we acknowledge a report, because at that point we would be guessing. We will tell you what we know as we know it.

We do not run a bug bounty and we do not pay for reports. Saying so plainly seems better than letting you find out after the work.

What we ask of you

One of these matters more than the rest. AuditSchedule is multi-tenant, and every workspace other than your own holds a real company's staffing and project data. Test against a workspace you created, never against somebody else's. If a flaw looks like it crosses between workspaces, stop as soon as you can tell that it does, and tell us what you saw rather than collecting more of it.

In scope

The AuditSchedule application at auditschedule.com, including its API and the authentication flows.

Out of scope

Out of scope does not mean unwelcome. It means we are unlikely to treat it as a vulnerability, and we would rather tell you that here than after you have spent an evening on it.

Safe harbour

If you make a good-faith effort to follow this policy while researching and reporting a vulnerability, we will treat your research as authorised. We will not bring or support legal action against you for it, and we will not report you to law enforcement. If a third party brings action against you for research that followed this policy, we will make it known that your conduct was authorised.

This applies to good faith. Accessing, taking or exposing another customer's data beyond what a demonstration needs, degrading the service, or extortion are not covered by anything on this page.

If you are not sure whether something is in scope or whether a test would cross a line, ask us first at security@auditschedule.com. We would rather answer the question than have you guess.

What we do not have

We have no third-party penetration test, no SOC 2 or ISO 27001 certification, and no formal incident response plan. We are a small team and we would rather say that here than imply a programme we do not run. A fuller account of what we do and do not have goes to customers' IT teams during procurement; ask us for it at security@auditschedule.com.

If you are a customer with a security question

Questions about how we handle your data, rather than reports of a flaw, are answered in our Privacy Policy, in Section 6 of our Terms, which is our data processing agreement, and on the sub-processors page. Anything those do not answer, email us.


security@auditschedule.com · Privacy Policy · Terms of Service · Sub-processors