We value the work of security researchers. If you believe you have found a vulnerability in our systems, we want to hear from you, and we will not pursue good-faith research conducted under this policy.

1. How to report

Email security@ulutengroup.com with enough detail to reproduce the issue — affected asset, steps, and impact. Encrypt sensitive details where possible.

2. What we ask

  • Act in good faith and avoid privacy violations, data destruction or service disruption.
  • Do not access, modify or exfiltrate more data than necessary to demonstrate the issue.
  • Give us reasonable time to investigate and remediate before public disclosure.

3. Our commitment

  • We will acknowledge your report and keep you informed of progress.
  • We will investigate and remediate valid issues promptly.
  • We will not take legal action against research conducted in good faith under this policy.

4. Out of scope

Social engineering, physical attacks, denial-of-service, and reports without a demonstrable security impact are out of scope.