Skip to content
ProductHow it worksSecurityPricing
Sign in Book a demo
ProductHow it worksSecurityPricing Sign in Book a demo
Appearance

Procursea Ltd

Vulnerability Disclosure Policy

How to report a security vulnerability, and what we commit to in return


Effective date: 24 August 2026 Last updated: 24 August 2026 Version: 1.0

1. Purpose

Procursea takes the security of its platform and of its customers’ data seriously. We welcome reports from security researchers and members of the public who identify potential vulnerabilities in our systems. This policy explains what is in scope, how to report a vulnerability, what we commit to in return, and what we ask of you.

2. Scope

This policy applies to the following systems, which are owned and operated by Procursea:

  • The Procursea web application at procursea.app, including its API endpoints.
  • The Procursea website at procursea.com.

The following are out of scope. Please do not test them under this policy:

  • Third-party services that Procursea relies on but does not control, including Stripe, Neon, Replit, Cloudinary, Microsoft and Google. Vulnerabilities in those platforms should be reported directly to the provider under their own disclosure programme.
  • Any system, domain or account not listed as in scope above.
  • The physical security of any premises, and the personal accounts, devices or property of Procursea personnel or customers.

3. How to report

Send your report by email to info@procursea.com with the subject line “Security vulnerability report”.

Please include:

  • A clear description of the vulnerability and the system affected.
  • The steps required to reproduce it, in enough detail that we can follow them.
  • The potential impact, as you assess it.
  • Any proof-of-concept code, requests, screenshots or logs that support the report.
  • The date and time of your testing, and the source IP address you tested from, so we can distinguish your activity from malicious traffic in our logs.
  • How you would like to be credited, if at all.

You may report anonymously. We will not require you to identify yourself as a condition of investigating a report.

4. Our commitments

  • We will acknowledge receipt of your report within three business days.
  • We will provide an initial assessment, including whether we have been able to reproduce the issue and our view of its severity, within ten business days.
  • We will keep you updated at least every fourteen days while the issue remains open.
  • We will tell you when the issue is resolved, and we will confirm if we decide not to act on a report and why.
  • We will not take legal action against you, or ask law enforcement to do so, in respect of research conducted in good faith and in accordance with this policy.

5. What we ask of you

Act in good faith and avoid causing harm. Specifically:

  • Do not access, modify, delete or exfiltrate data belonging to any person other than yourself. If you inadvertently encounter customer data, stop immediately, do not save or copy it, and tell us in your report.
  • Do not degrade, disrupt or interrupt the Service. Do not perform denial-of-service testing, automated high-volume scanning, or load testing.
  • Do not use social engineering, phishing, or physical intrusion against Procursea personnel, customers or premises.
  • Use only accounts you own or have explicit permission to test. Do not attempt to access other users’ accounts.
  • Give us a reasonable opportunity to resolve the issue before disclosing it publicly. We ask for 90 days from the date we acknowledge your report, and we are happy to discuss a different timeline where the circumstances warrant it.
  • Comply with all applicable laws.

Research conducted outside these limits falls outside this policy and outside the assurances in section 4.

6. Findings we generally do not act on

The following are typically not treated as vulnerabilities unless you can demonstrate a concrete security impact:

  • Missing security headers or cookie flags with no demonstrated exploit.
  • Reports produced solely by an automated scanner, without validation or a working proof of concept.
  • Weaknesses in email configuration such as SPF, DKIM or DMARC, absent a demonstrated attack.
  • Disclosure of software version numbers or of information available in public sources.
  • Self-inflicted issues that require the victim to paste code into a browser console or otherwise attack their own account.
  • Vulnerabilities affecting only outdated or unsupported browsers.
  • Rate limiting on endpoints where no sensitive action is performed.

Please do report these if you can show real-world impact. The list describes our default assessment, not a refusal to look.

7. Recognition

Procursea does not currently operate a paid bug bounty programme and does not offer financial rewards for vulnerability reports. Where a report leads to a fix, we are glad to credit the reporter by name in our release notes if they wish.

8. Review

This policy is reviewed at least annually by the policy owner, and following any material change to the systems in scope.

9. Contact

Procursea Ltd
United Kingdom
Email: info@procursea.com

Copyright © 2026 Procursea Ltd. All rights reserved.

Procursea

Serious procurement software, purpose-built for superyachts.

Sign in

Product

  • Platform
  • Ai Procurement
  • Visual Scan
  • Supplier Network
  • Mobile App

Company

  • Pricing
  • Contact

Resources

  • How it works
  • FAQ
  • Tutorials

Legal

  • Privacy
  • Terms
  • Cookies
  • Information Security
  • Vulnerability Disclosure

Network

  • Supplier Network Coming soon
  • A new procurement network connecting marine suppliers with the vessels they serve.
Download on the App Store

Copyright © 2026 Procursea Ltd. All rights reserved.

Monaco · Antibes · Palma

Cookies

We use no tracking or analytics cookies. The interactive demo is hosted by Appetize, which sets its own cookie when you choose to load it. No tracking or analytics. The demo sets a third-party cookie if you load it. Cookie Policy