Skip to content

Responsible Disclosure

We welcome reports of security vulnerabilities in Condulo's website and application. This page explains how to reach us and what to expect.

Last Updated: August 26, 2026

1. How to report

Email security@condulo.com. Please include enough detail for us to reproduce the issue: the affected URL or endpoint, the steps you took, and what you observed. If a proof of concept is necessary, keep it to the minimum needed to demonstrate the problem.

Please report privately and give us a reasonable opportunity to remediate before any public disclosure. We will not take legal action against researchers who follow this policy in good faith.

2. What we commit to

  • We acknowledge receipt of your report, and confirm we have it.
  • We tell you whether we consider the issue in scope, and give you our assessment of its severity.
  • We keep you updated on remediation progress, and let you know when the issue is resolved.
  • We credit you when the issue is fixed, if you would like to be credited.

We do not currently operate a paid bug-bounty programme, and we do not offer monetary rewards.

3. Scope

In scope:

  • The condulo.com website.
  • The Condulo application at app.condulo.com.
  • The participant capture experience at talk.condulo.com.
  • The public research catalogue at research.condulo.com.

Out of scope, and please do not test these:

  • Denial-of-service, volumetric, or load testing of any kind.
  • Social engineering, phishing, or physical attacks against Condulo staff, participants or customers.
  • Any testing that accesses, modifies, exfiltrates or destroys data belonging to another person — including interview recordings, transcripts and participant personal data. If you find a way to reach data that is not yours, stop and tell us rather than confirming the extent of the access.
  • Findings that come only from automated scanner output, without a demonstrated impact.
  • Vulnerabilities in third-party services we use, which should be reported to those providers directly.

4. A note on participant data

Condulo processes video and audio recordings of research participants. That data is sensitive, and participants have given consent for a specific research purpose only. If your testing brings you into contact with it, stop immediately, do not retain or share any copy, and tell us what happened. We will treat a good-faith report of accidental exposure as a report, not an incident caused by you.

5. Machine-readable contact

Our security contact is also published at /.well-known/security.txt in the format described by RFC 9116.