Skip to content
AshmereSoftware
Security

Reporting a vulnerability.

Ashmere builds security-relevant software, including Sentinel and Kestrel CAD's records systems. If you've found a genuine security issue in something we run or publish, we want to hear about it directly.

Where to report

Email [email protected] with a description of the issue, the project or system it affects, and clear steps to reproduce it. Include your contact details if you'd like to be kept updated or credited once it's resolved.

Scope

This covers software Ashmere Software builds and operates — this website, and the Kestrel CAD, Sentinel and Beacon platforms. S.W.A.N.'s public site is a separate deployment; if you find an issue there, the same address will make sure it reaches the right people.

We don't currently run a bug bounty programme or offer paid rewards for reports. We do take every genuine report seriously and will acknowledge receipt.

Responsible disclosure

Please give us a reasonable opportunity to investigate and remediate an issue before sharing it publicly. Avoid accessing, modifying or deleting data that isn't yours, and avoid any action that could degrade a live service for other people using it. Reports made in good faith, within these limits, won't result in legal action from us.

security.txt

A machine-readable /.well-known/security.txt (RFC 9116) is published pointing back to this page and the address above.