Reporting a Security Issue
Last updated: 20 August 2026
How to report
Email hello@twincoretech.com with “Security report” in the subject line. Please include what you found, where you found it, and enough detail for us to reproduce it. The same contact is published, in machine-readable form, at /.well-known/security.txt.
What you can expect from us
- We acknowledge your report within five working days.
- We tell you whether we have reproduced the issue, and what we intend to do about it.
- We will not take legal action against you, or ask anyone else to, for research carried out in good faith and within this policy.
- We are happy to credit you when the issue is resolved, if you would like us to.
What we ask of you
- Give us a reasonable opportunity to fix the issue before disclosing it publicly.
- Do not access, modify or delete data that is not yours. If you come across personal data, stop and tell us.
- Do not run denial-of-service tests, send bulk traffic, or use social engineering, phishing or physical attacks against our people.
- Use only your own accounts and test data.
Scope
This policy covers www.twincoretech.com and the services we operate on Omadeas. Issues in third-party products we merely use are best reported to that vendor, though we are glad to be told.
We do not currently run a paid bug bounty. This is a disclosure route, not a rewards programme.
If any of this sounds like the operation you’re trying to run, let’s talk.
We work with leadership teams who’ve outgrown the patchwork stage. You don’t need a perfectly-formed brief, most engagements start from a single, specific problem.
The first session is a conversation, not a pitch. We listen. If there’s a fit, we’ll put a clear proposal on the table within a fortnight.