Responsible Disclosure Policy
Last updated: 30 August 2026
We're a security company, so we understand if you find something on ravnsec.com you want to tell us about. This page says how.
RAVN Security is a trading name of JBANORDIC (org. no. 199312274658). JBANORDIC is who you report to and who responds to your report — which is why the text below says JBANORDIC.
Scope
This policy covers vulnerabilities in the ravnsec.com website itself — not third-party services we link to, and not customer systems we test on someone else's behalf. We only accept reports about our own infrastructure.
What's okay to test
Please report vulnerabilities you find through passive observation or testing that does not disrupt other visitors or our operations: misconfiguration, information disclosure, authentication or authorisation flaws and the like.
- Avoid anything that could affect other visitors or our availability — no denial-of-service (DoS/DDoS), no bulk automated scanning.
- Do not access, modify or delete data that is not your own. If you can demonstrate a vulnerability with a minimal test case, do that instead.
- Do not attempt social engineering (phishing, vishing) against our staff.
- Do not otherwise break the law — this is not a licence to do anything you like.
Safe harbour
Stay within this policy and we treat your testing as authorised under our terms of service, and will not pursue legal action against you for it. That is conditional on good faith: discover, report, stop testing once you've found something — not keep digging after a vulnerability is confirmed.
How to report
Email hi@ravnsec.com with what you found, how we can reproduce it, and what impact you believe it has. Feel free to send an encrypted report if the content is sensitive — reach out and we'll arrange it.
What to expect
We acknowledge receipt within five business days, and follow up with our assessment and a remediation timeline as soon as we can. We keep you updated until the issue is closed.
Reward
We do not run a bug bounty programme and do not pay for reports. We're happy to credit you publicly if you'd like that, and otherwise keep you anonymous.