We value the work of security researchers. If you believe you have found a vulnerability in our systems, we want to hear from you, and we will not pursue good-faith research conducted under this policy.
1. How to report
Email security@ulutengroup.com with enough detail to reproduce the issue — affected asset, steps, and impact. Encrypt sensitive details where possible.
2. What we ask
- Act in good faith and avoid privacy violations, data destruction or service disruption.
- Do not access, modify or exfiltrate more data than necessary to demonstrate the issue.
- Give us reasonable time to investigate and remediate before public disclosure.
3. Our commitment
- We will acknowledge your report and keep you informed of progress.
- We will investigate and remediate valid issues promptly.
- We will not take legal action against research conducted in good faith under this policy.
4. Out of scope
Social engineering, physical attacks, denial-of-service, and reports without a demonstrable security impact are out of scope.