Simmissimmis inspect the source
capabilities architecture roadmap blog docs about
join cloud waitlist inspect the source

security

How to report vulnerabilities and conduct responsible security research.

REPORT A VULNERABILITY

tell us what broke, and how.

For sensitive or exploitable findings, send an initial private notice to info@simm.is with the affected surface, likely impact, and your preferred secure contact method. Do not include exploit code, credentials, personal information, or other sensitive evidence in ordinary email. We will arrange a safer exchange if more detail is needed.

For non-sensitive security bugs, hardening suggestions, or documentation problems, open an issue in the relevant public stack repository on GitHub.

Do not put exploit details, credentials, secrets, sensitive data, or instructions that could put users at risk in a public issue.

report privately view public repositories

responsible security research

You may investigate the public Site and published source that you are lawfully entitled to use. Testing an invited evaluation environment, another user’s account, or any non-public Simmis environment requires prior written authorization that identifies the permitted scope.

Act in good faith and minimize access and disruption. Stop if you encounter personal information, confidential material, credentials, or evidence of active compromise. Do not:

  • use social engineering, phishing, physical intrusion, denial-of-service, malware, or destructive techniques;
  • access, alter, retain, or disclose data beyond the minimum needed to demonstrate the issue;
  • test third-party providers or infrastructure without their authorization; or
  • publish an exploitable finding before Simmis and affected providers have had a reasonable opportunity to investigate.

Simmis does not currently offer a bug bounty programme, guaranteed response time, or guaranteed reward. Simmis cannot authorize activity against third-party systems or waive rights belonging to other people.

what happens after a report

We will use the contact details you provide to clarify the report, assess affected versions and environments, coordinate with relevant maintainers or providers, and communicate a remediation or disclosure path where practicable. Please preserve evidence and tell us before sharing sensitive details with anyone else.

Security reports and related personal information are handled under the Privacy Notice. Confidentiality, incident notification, and remediation duties for an invited pilot are governed by its signed agreement.

REPORT
REVIEW
RESOLVE
RELATED known limits roadmap releases

LAST UPDATED · 2026-08-05 · VERSION · 2026-08-05.1 · QUESTIONS · INFO@SIMM.IS

Simmissimmis

Understand

  • capabilities
  • architecture
  • faq
  • vision
  • about us

Go deeper

  • docs
  • roadmap
  • blog
  • releases

Connect

  • contact us
  • github

Legal

  • terms
  • privacy
  • licence
  • security
© 2026 simmis · All rights reserved. Shared context and controlled change.