We built a security platform. Before real customers put their asset data in it, we would rather have people who actually know this field take it apart. Find something serious, tell us, and the account is yours.
SimpleSecurity is an all-in-one information security and compliance platform for Nordic SMBs — asset register, vulnerability scanning, uptime, certificate and email monitoring, risk register, incidents, supplier review and automated evidence for ISO 27001 and NIS2. It is built and run by one person: a working CISO with sixteen years in the field.
We are pre-launch. There is no customer data in the platform yet. That makes right now the only moment when finding a problem is cheap — for us and for the people who will trust it later. A security vendor that never invites people to look is asking you to take its word for it. We would rather not.
Report something we judge serious and you get an MVP account: every service on the platform unlocked, with a 20-asset cap, free for six months. It is not a trial — it is the full product, including the modules that normally sit on the top tier.
We will not pursue or support legal action against anyone who researches in good faith within this policy. If you follow the scope and the rules below, we consider your testing authorised, and we will say so in writing if anyone ever asks.
If you accidentally step outside scope — it happens — stop, tell us what happened, and delete anything you pulled down. Telling us promptly keeps you inside the safe harbour. Quietly continuing does not.
We judge every report on its own merits — but so that "serious" is not just a word, here is what clears the bar in practice:
Most of what is worth finding here is behind a login — tenant isolation, access control, privilege boundaries. You cannot test that from the outside, so the account is part of the event, not the prize.
Public registration is closed. The link below carries the event code and opens a signup form anyway. You get your own isolated tenant with uptime and certificate monitoring on one asset — no other tenant's data is reachable from it, which is rather the point of what we would like you to test.
Create a researcher accountCreating an account through that link means you accept the rules and scope above. Accounts made for this event are removed when it closes — except the ones that found something, which keep the MVP access described earlier.
Email us. Include steps to reproduce, the impact as you see it, and how you would like to be credited if it qualifies.
security@simplesecurity.seWe acknowledge every report within 72 hours. Reports go straight into our own incident workflow — the same one the product ships to customers — so nothing sits in an inbox unread.
Hall of fame security.txtThis event runs for a limited period and closes once we are satisfied with the coverage. Responsible disclosure at security@simplesecurity.se stays open permanently, event or no event.