Reporting a security issue
Effective 30 July 2026
If you have found a security vulnerability in Chartping, we want to hear about it before anyone else does. This page tells you where to send it and what we undertake in return.
Where to send it
Email [email protected]. Please include enough for us to reproduce it — the affected hostname or app, the steps, and what you were able to reach. If you would rather not send details by email first, send a short note and we will arrange another channel.
Please do not open a public issue, post it publicly, or discuss it with others until we have had a chance to fix it.
What we undertake
- We acknowledge your report within five business days.
- We keep you informed through triage and fix, rather than going quiet on you.
- We credit you when the issue is resolved, if you would like to be credited.
- We will not pursue or support legal action against good-faith research that respects other people's data, avoids disrupting the service, and gives us a reasonable opportunity to fix the issue before it is disclosed.
We do not run a bug bounty and cannot offer payment. That is a resourcing limit, not a judgement about the value of the report.
In scope
- Our hostnames: chartping.com, and the account, API and portal hostnames under it.
- The Chartping mobile apps and the desktop agent.
Out of scope
- Anything that requires you to access, modify or retain another person's data. Demonstrate the flaw against your own account; if that is genuinely not possible, tell us and stop there.
- Denial of service, load or stress testing, and anything else that degrades the service for other people.
- Social engineering of our staff, our users or our providers, and physical attacks.
- Findings from automated scanners with no demonstrated impact, and reports that consist only of a scanner report.
- Vulnerabilities in third-party services we use, which belong to those providers' own disclosure programmes.
Suspected compromise of your own account
That is not a research report and should not wait — email [email protected] and say so in the subject line. Our Terms ask you to tell us about any suspected compromise of your credentials.
If personal data is affected
Where an incident affects personal data, we assess it and, where the law requires, report it to the Information Commissioner's Office and tell the people affected. What we hold and who receives it is described in our Privacy Notice, and our subprocessors are listed at /legal/subprocessors.
Contact
TrendSoft Ltd, Aa House 54, 27 Old Gloucester Street, London, WC1N 3AX, United Kingdom. Company No. 16144241. Security: [email protected]. General: [email protected].