Unidus Consulting LtdYou need us !

Report a vulnerability

Do you think you have found a security flaw in software from Unidus Consulting, or on this site? Please tell us. This page explains how, and what we do next.

What is in scope

Our clients' own systems are out of scope: if the flaw lies in their installation rather than in our software, write to us anyway and we will let them know.

How to reach us

Write to securite@unidus-consulting.com, in English or French. So that we can act quickly, please include:

  1. the software or page concerned, and its version if you know it;
  2. what the flaw allows;
  3. the steps to reproduce it;
  4. how you would like to be credited, or whether you prefer to remain anonymous.

What we commit to

We do not pay bounties. We would rather say so plainly than let you hope otherwise.

What we ask of you

Our commitment to you

If you act in good faith and within these rules, we will not take any legal action against you, nor ask anyone else to. If a third party challenged you over this research, we would state publicly that you acted with our consent.

If we do not reply

If you have no reply from us within 10 working days, write again to contact@unidus-consulting.com. You may also contact CERT-MU, the national incident response team of Mauritius, where our company is established.