Security
We would rather hear about a problem from you than from an attacker. This page explains how to reach our security team, what we commit to in return, and who processes data on our behalf.
Effective September 11, 2026 · Operated by Secuur LLC
Reporting a vulnerability
Email [email protected]. Include enough detail to reproduce the issue — the affected URL or endpoint, the steps, and what you observed. A machine-readable version of this contact information is published at /.well-known/security.txt per RFC 9116.
If you would prefer to encrypt your report, say so in a first message and we will exchange keys before you send details. We do not publish a long-lived PGP key we cannot guarantee we will rotate; asking first means you always encrypt to a key we actually hold.
What we commit to
- We acknowledge reports within 3 business days.
- We give an initial assessment, including whether we consider it in scope, within 10 business days.
- We keep you updated while we remediate, and tell you when a fix ships.
- We will credit you by name in our advisory if you want the credit, and stay quiet about you if you do not.
- We will not pursue or support legal action against you for research conducted in good faith under this policy.
Safe harbour
We consider security research conducted in accordance with this policy to be authorised, and will not treat it as a violation of our Terms of Service. Good faith means: you test only against assets in scope, you stop as soon as you have confirmed an issue, you do not access, modify, exfiltrate or destroy data that is not yours, you do not degrade the service for others, and you give us a reasonable opportunity to fix the issue before disclosing it publicly.
In scope
secuur.meandwww.secuur.me— the marketing site and scan API.app.secuur.me— the customer dashboard.
Out of scope
- Denial-of-service, volumetric testing, and any automated scanning that degrades availability.
- Social engineering, phishing or physical attacks against our staff or suppliers.
- Reports produced solely by an automated scanner with no demonstrated impact.
- Findings in third-party services we do not operate — report those to the operator.
- Missing hardening headers or best-practice recommendations with no demonstrated exploit path.
We do not currently operate a paid bug bounty. Disclosure under this policy is voluntary and unpaid, and we will say so plainly rather than imply a reward that does not exist.
How we handle your data
- In transit. All secuur.me traffic is served over TLS 1.3 with a hybrid post-quantum key exchange (X25519MLKEM768, NIST FIPS 203). Our own current grade is published in the case study.
- At rest. Application data sits on encrypted volumes on infrastructure we administer. Card data never reaches us — it goes directly to Stripe.
- Sessions. Session identifiers are server-issued HttpOnly, Secure, SameSite=Lax cookies. A client cannot nominate its own session id.
- Access. Administrative access to production is limited to named operators using key-based authentication.
- Scanning. A readiness scan is an unauthenticated TLS handshake. It sends no payloads, attempts no exploitation, and makes no authenticated request against your systems.
Subprocessors
These third parties process data on our behalf. We update this list when it changes.
| Subprocessor | Purpose | Data involved |
|---|---|---|
| Cloudflare, Inc. | DNS, CDN, TLS termination and DDoS protection | Request metadata, IP addresses |
| OVH US LLC | Application hosting for the marketing site, scan API and customer dashboard | Account records, scan results, session data |
| Stripe, Inc. | Payment processing and subscription billing | Billing contact and payment method — held by Stripe, never stored by Secuur |
| Telnyx LLC | SMS delivery for booking confirmations and alerts | Phone number, message content |
| Moonshot AI (Kimi) | Language-model inference behind the on-site assistant | Assistant conversation text you choose to send |
We also operate the following ourselves rather than delegating it, listed here so the picture is complete:
| Service | Purpose | Data involved |
|---|---|---|
| Secuur mail (Stalwart) | Transactional and notification email, self-hosted on infrastructure we control | Email address, message content |
Certifications
Secuur LLC does not currently hold a SOC 2, ISO 27001 or FedRAMP authorisation, and we will not imply otherwise. We help customers produce evidence for those programmes; we are not ourselves certified under them. If that changes, this page changes with it.
Contact
Security: [email protected] · General: [email protected]