Vicarium

Vulnerability disclosure policy

Last changed on 26-09-2026

If you believe you have found a vulnerability in Vicarium, tell us. We run a service that holds the access credentials of business owners; a report is worth more to us than silence, and we treat it seriously.

Where to report

info@vicarium.eu, with "vulnerability" in the subject. Encryption is welcome; ask us for a key first.

What we do

What we ask of you

What we do not do

We pay no bounty. If you stay within the above, we will not take legal action against you.

What you need not report

Findings from an automated scan without demonstrated impact, missing security headers without a working scenario, and issues that only occur on outdated browsers.