Reporting a vulnerability
Last reviewed 20 September 2026 · Node Logic, trading as AuditSchedule
If you have found a security problem in AuditSchedule, we want to hear about it. This page says how to tell us, what we will do about it, what we ask of you in return, and what protection you have for looking in the first place.
How to report
Email security@auditschedule.com. Tell us what you found, how to reproduce it, and what it would let someone do. A short description with exact steps is worth more to us than a long report without them.
We do not publish a PGP key, so treat the email as unencrypted and send us only what is needed to demonstrate the problem.
The same contact details are published in machine-readable form at /.well-known/security.txt.
What we commit to
- We acknowledge your report within 5 working days.
- We give you a substantive reply within 10 working days: what we found, whether we agree it is a vulnerability, and what we are doing.
- We keep you updated until it is resolved, and tell you when it is fixed.
- If you want the credit, we name you when we publish the fix in our What's New notes.
We will not give you a fix date when we acknowledge a report, because at that point we would be guessing. We will tell you what we know as we know it.
We do not run a bug bounty and we do not pay for reports. Saying so plainly seems better than letting you find out after the work.
What we ask of you
One of these matters more than the rest. AuditSchedule is multi-tenant, and every workspace other than your own holds a real company's staffing and project data. Test against a workspace you created, never against somebody else's. If a flaw looks like it crosses between workspaces, stop as soon as you can tell that it does, and tell us what you saw rather than collecting more of it.
- Report what you find promptly, and give us 90 days to fix it before you publish.
- Take only the minimum data needed to demonstrate the problem, and delete it afterwards.
- Do not degrade the service for anyone else.
- Do not modify or delete data that is not yours.
In scope
The AuditSchedule application at auditschedule.com, including its API and the authentication flows.
Out of scope
- The infrastructure our providers run. Our sub-processors each operate their own disclosure programme, and a flaw in one of their platforms should go to them.
- Denial of service, volumetric testing, and anything else that works by exhausting a resource.
- Social engineering of our staff, our customers or our providers, and any physical attack.
- Automated scanner output with no demonstrated impact, including missing headers, cookie flags and best-practice findings with no route to exploiting them.
- Email configuration findings (SPF, DKIM, DMARC) without a working spoofing demonstration.
Out of scope does not mean unwelcome. It means we are unlikely to treat it as a vulnerability, and we would rather tell you that here than after you have spent an evening on it.
Safe harbour
If you make a good-faith effort to follow this policy while researching and reporting a vulnerability, we will treat your research as authorised. We will not bring or support legal action against you for it, and we will not report you to law enforcement. If a third party brings action against you for research that followed this policy, we will make it known that your conduct was authorised.
This applies to good faith. Accessing, taking or exposing another customer's data beyond what a demonstration needs, degrading the service, or extortion are not covered by anything on this page.
If you are not sure whether something is in scope or whether a test would cross a line, ask us first at security@auditschedule.com. We would rather answer the question than have you guess.
What we do not have
We have no third-party penetration test, no SOC 2 or ISO 27001 certification, and no formal incident response plan. We are a small team and we would rather say that here than imply a programme we do not run. A fuller account of what we do and do not have goes to customers' IT teams during procurement; ask us for it at security@auditschedule.com.
If you are a customer with a security question
Questions about how we handle your data, rather than reports of a flaw, are answered in our Privacy Policy, in Section 6 of our Terms, which is our data processing agreement, and on the sub-processors page. Anything those do not answer, email us.
security@auditschedule.com · Privacy Policy · Terms of Service · Sub-processors