Skip to content
Legal

Responsible Disclosure Policy

How to report a security vulnerability to Certivo, what you can expect from us, and the safe-harbour we offer to good-faith researchers.

1. Our commitment

We value the work of the security community and treat vulnerability reports as a priority. If you have found a security issue affecting Certivo, we want to hear about it and will work with you to understand and resolve it quickly.

2. How to report

Email security@certivo.uk with a clear description of the issue. To help us triage, please include:

  • the affected URL, endpoint, or component;
  • the type of issue and its potential impact;
  • step-by-step instructions to reproduce it, and any proof-of-concept; and
  • your contact details so we can follow up.

Please do not disclose the issue publicly, or to any third party, until we have had a reasonable opportunity to remediate it.

3. What to expect from us

  • We acknowledge your report within two business days.
  • We provide an initial assessment and keep you informed of remediation progress.
  • We will credit you, with your permission, once the issue is resolved.

4. Rules of engagement

To keep testing safe for everyone, please:

  • act in good faith and avoid privacy violations, data destruction, or service disruption;
  • only interact with accounts you own or have explicit permission to test;
  • do not access, modify, or exfiltrate data that does not belong to you — stop and report as soon as you confirm a vulnerability;
  • do not run denial-of-service, spam, social-engineering or physical-security tests;
  • use the sandbox and your own test data wherever possible.

5. Safe harbour

If you make a good-faith effort to comply with this policy during your research, we will consider your testing to be authorised, will not pursue or support legal action against you for it, and will work with you to understand and resolve the issue quickly. This safe-harbour does not extend to actions that are unlawful, that violate the privacy of others, or that damage or degrade the service or its data.

6. Scope

This policy covers the Certivo production web application and API and this marketing site. Third-party services that Certivo relies on are governed by their own disclosure programmes; please report issues in those services to the relevant provider. Our current infrastructure sub-processors are listed on the Sub-processors page.

7. Related policies

See our Information Security Statement and Acceptable Use Policy. For non-security issues, please use our Complaints process.

Company details

Registered entity namePuzzle Piece Ventures Ltd
Company numberHE 469272
Registered office[Registered office — Cyprus, to be confirmed]
JurisdictionRepublic of Cyprus
Governing lawthe Republic of Cyprus
GroupOnyxOne Group
General enquiriesmanagement@certivo.uk

Any bracketed value is a registration detail to be confirmed by the operating entity.

Last updated: 22 July 2026.

This document is published by Certivo (Puzzle Piece Ventures Ltd) and is governed by the laws of the Republic of Cyprus. Questions about it can be directed to management@certivo.uk. It does not constitute legal advice; you should take your own advice on how it applies to your circumstances.