Security

Responsible Disclosure

Updated: 2026-07-01

SveaSMS welcomes serious security researchers. The following rules must be followed strictly. Breach is treated as unauthorised intrusion and may lead to legal action.

1. Reporting

Send reports to support@sveasms.com. Include PoC, impact, reproduction steps and environment. Do not use third-party platforms without written consent.

2. Testing rules

  • No social engineering, phishing or physical access.
  • No DoS/DDoS, no brute force, no automated scanning that impacts performance.
  • No data exfiltration, no deletion or modification of data. On accidental access — stop immediately and report.
  • Test accounts only (create your own). Do not touch other accounts or recipients.
  • No publication before written approval.

3. Safe harbor (limited)

Reports made in good faith following these rules mean the Company will not take legal action against the researcher for the research itself. Safe harbor does not cover breaches of section 2 or of law.

4. Reward

The Company does not currently run a formal bug bounty programme. Any reward is entirely voluntary and determined unilaterally by the Company based on severity and quality.

5. Confidentiality

Reports and all related communication are confidential. Publication may only occur at the earliest 90 days after reporting, subject to the Company's written approval.