Vulnerability Disclosure Policy

If you have found a security problem in something Available runs, we want to hear about it, and this page tells you how to tell us without wondering whether you should.

How to report

Email security@available.dk. Please include enough for us to reproduce the issue — a URL or endpoint, the steps you took, and what you saw. Screenshots or a short recording help. Write in Danish or English, whichever you prefer.

You do not need to encrypt your report, but if you would rather, say so and we will arrange a channel.

What we commit to

Acknowledgement Within 2 business days
First assessment Within 5 business days, including our view of severity
Progress updates At least every 10 business days until it is closed

Confirmed issues are remediated on the timelines in our internal vulnerability management procedure, driven by severity rather than by who reported them. We will tell you when a fix has shipped, and we are happy to credit you by name if you would like that.

Safe harbour

We will not pursue legal action against you, or ask anyone else to, for security research carried out in good faith under this policy. That is the point of writing this down: a researcher who is unsure whether reporting is safe usually says nothing, and we would rather know.

Good faith means:

  • You stop as soon as you have confirmed a problem exists, and do not go further into our systems or our clients' data than that requires.
  • You do not access, modify, download or retain personal data belonging to anyone else. If you come across it, stop and tell us what you saw so we can assess it.
  • You do not degrade our services — no denial of service, no load or stress testing, no spam or social engineering of our staff or clients.
  • You give us reasonable time to fix the issue before disclosing it publicly. We do not set a fixed embargo, and will agree a date with you.

Scope

In scope: services Available operates — available.dk, trust.available.dk, mit.available.dk, core.available.dk, zendesk.available.dk, ai.available.dk, connect.available.dk, status.available.dk, and our other product services.

Out of scope: our clients' own systems, including the Zendesk instances we work in on their behalf — those belong to them, and we cannot authorise testing against them. Also out of scope are our suppliers' own platforms; report those to the supplier. Findings that are only theoretical, or that amount to missing hardening headers with no demonstrated impact, are welcome but are usually handled as improvements rather than vulnerabilities.

No bug bounty

We do not pay for reports. We are a small company and would rather be honest about that than imply a reward that is not there. Credit, a genuine thank-you, and a fix are what we can offer.

If it turns out to be a breach

A report that involves personal data is handled under our incident response procedure, including any notification obligations we have to clients or to Datatilsynet. We will tell you if your report led to that, unless doing so would compromise the response.

Version 0.1 · Last reviewed 2026-09-03