Security Vulnerability Disclosure Policy
Last updated: 11/09/2026
Classification: Public
We take the security of our products seriously. If you believe you've found a security vulnerability, or have evidence that a vulnerability is being actively exploited, we want to hear from you.
1. How to report
Contact: https://annex19.com/contact
PGP key: https://annex19.com/pgp-key
Fingerprint: 1270 9462 3E9C E228 6B36 177E 08BE 27EE 62D6 E8C3
Languages: English
Reporting sensitive vulnerabilities
If your report includes details of an unpatched or actively exploited vulnerability, please encrypt it using our PGP key before emailing it to us:
Download our public key from the link above.
Verify the fingerprint matches the one published on this page before trusting the key — don't rely solely on a key found elsewhere.
Encrypt your report to that key.
Send the encrypted message to via https://annex19.com/contact
Encryption is optional for general or low-sensitivity reports, but strongly recommended for anything involving an unpatched vulnerability or evidence of active exploitation.
Encrypting vs. signing: Encrypting your report to our public key ensures only we can read it. If you'd also like to prove the report came from you (and let us verify it hasn't been tampered with), you can additionally sign it with your own PGP key before encrypting. Signing is optional and only meaningful if you have your own key pair — it authenticates the sender, it does not replace encryption.
Please include as much of the following as you can:
Product and version affected
Description of the vulnerability
Steps to reproduce, or a proof of concept, if available
Any evidence suggesting the vulnerability is being actively exploited (e.g., logs, indicators of compromise)
Your contact details, if you'd like a response
2. What to expect
Acknowledgement of your report - Within [24–48 hours]
Initial review - Within [5–10 business days]
Follow-up or resolution update - As the assessment progresses
We review every report in good faith. Depending on the outcome of our assessment, a confirmed vulnerability may trigger further internal processes, including regulatory reporting where required by law.
3. Good-faith research
We do not currently offer a formal safe-harbour commitment or bug bounty program. We ask that researchers:
Avoid accessing, modifying, or deleting data that isn't their own
Avoid degrading the availability of our services
Give us a reasonable opportunity to investigate and address a report before any public disclosure
Not use automated scanning that could impact production systems without prior contact