Security
Last updated September 2026
Reporting a vulnerability
Email contactikstrategic@gmail.com with the subject line “Security”. Please include:
- the URL or system affected, and the type of issue;
- the steps to reproduce it, with any request/response detail or screenshots;
- an assessment of the impact, if you have one.
We will acknowledge your report within five business days and keep you updated as we investigate and fix it. We are a small team and do not currently run a paid bug-bounty programme, but we are grateful for reports and will credit you if you would like us to.
Testing guidelines
When investigating, please:
- stay within www.ikstrategic.com and systems clearly operated by IK Strategic Services;
- avoid automated scanning that degrades service, and stop at the point you have proven an issue;
- never access, modify, or delete data that is not yours, and never run denial-of-service, spam, or social-engineering attacks;
- give us a reasonable window to remediate before disclosing the issue publicly.
Safe harbour
If you make a good-faith effort to follow this policy, we will treat your research as authorised, we will not pursue or support legal action against you for it, and we will work with you to understand and resolve the issue quickly.
How we build
Security is part of delivery for us, not a phase at the end — human review of every AI-assisted change, continuous automated testing against each build, and least-privilege access to client data. More on that on our How we build section.