Security
How this website is built and defended, what Anquin does not claim, and how to report a vulnerability if you find one.
How this website is built and defended, what Anquin does not claim, and how to report a vulnerability if you find one.
These are properties of the site as it runs today, not a roadmap. Each one can be checked from outside.
If any of that changes, this page changes with it. Until then, take the absence of a claim as the claim.
This policy covers the Anquin corporate website and its subdomains.
Email us. Please include enough detail to reproduce the issue: the affected URL, the steps you took, and what you observed.
If a report contains sensitive detail, say so and we will arrange an encrypted channel before you send it.
Send reports to
If you make a good-faith effort to comply with this policy during your research, we will treat your activity as authorised. We will not pursue or support legal action against you in relation to it, and if a third party brings action against you for research conducted under this policy, we will make it known that your activity was authorised.
Good faith means following the scope and the requests above. Activity that damages systems, degrades service for others, or accesses data belonging to third parties falls outside this protection.
Anquin does not currently operate a paid bug bounty. Reports are still welcome and are taken seriously.