Limited-time event

Securing with Community

We built a security platform. Before real customers put their asset data in it, we would rather have people who actually know this field take it apart. Find something serious, tell us, and the account is yours.

Why we are doing this

SimpleSecurity is an all-in-one information security and compliance platform for Nordic SMBs — asset register, vulnerability scanning, uptime, certificate and email monitoring, risk register, incidents, supplier review and automated evidence for ISO 27001 and NIS2. It is built and run by one person: a working CISO with sixteen years in the field.

We are pre-launch. There is no customer data in the platform yet. That makes right now the only moment when finding a problem is cheap — for us and for the people who will trust it later. A security vendor that never invites people to look is asking you to take its word for it. We would rather not.

We do not run a paid bug bounty — this is a one-person, bootstrapped company and we are not going to pretend otherwise. What we offer instead is a real account, public credit if you want it, and a published account of what you found and what we fixed.

The MVP account

Report something we judge serious and you get an MVP account: every service on the platform unlocked, with a 20-asset cap, free for six months. It is not a trial — it is the full product, including the modules that normally sit on the top tier.

All services
Compliance, risk, vendor, incidents, policies, change register, awareness training, and every monitor
20 assets
Enough to run something real, capped because this is a thank-you rather than a free enterprise licence
6 months
From the day it is granted. No card, no auto-renewal, nothing to cancel
Your name
On our hall of fame, if you want it. Entirely optional — plenty of people prefer not to

Scope

In scope

  • simplesecurity.se and the logged-in application
  • Our API endpoints, reached with your own account
  • Authentication, session handling and multi-factor flows
  • Anything that lets one tenant see or touch another tenant's data
  • The public vendor-assessment and training portals

Out of scope

  • Other people's data. If you find a way in, stop and report it — do not go through it
  • Denial of service, load testing, resource exhaustion
  • Social engineering, phishing our founder, physical access
  • Findings against AWS itself, or third-party services we merely consume
  • Automated scanner output pasted without a working proof of concept
Expect the WAF to fight you. There is a real WAF and rate limiting in front of the site. If you get blocked, that is the product working — mention it in your report rather than assuming the platform is broken.

Safe harbour

We will not pursue or support legal action against anyone who researches in good faith within this policy. If you follow the scope and the rules below, we consider your testing authorised, and we will say so in writing if anyone ever asks.

If you accidentally step outside scope — it happens — stop, tell us what happened, and delete anything you pulled down. Telling us promptly keeps you inside the safe harbour. Quietly continuing does not.

Rules

What we consider serious

We judge every report on its own merits — but so that "serious" is not just a word, here is what clears the bar in practice:

Missing security headers, outdated library versions with no working exploit, and self-XSS do not qualify on their own — but if you can chain them into one of the above, that absolutely counts, and we would rather see it. The final call is ours, and we will explain our reasoning either way.

Get your test account

Most of what is worth finding here is behind a login — tenant isolation, access control, privilege boundaries. You cannot test that from the outside, so the account is part of the event, not the prize.

Public registration is closed. The link below carries the event code and opens a signup form anyway. You get your own isolated tenant with uptime and certificate monitoring on one asset — no other tenant's data is reachable from it, which is rather the point of what we would like you to test.

Create a researcher account

Creating an account through that link means you accept the rules and scope above. Accounts made for this event are removed when it closes — except the ones that found something, which keep the MVP access described earlier.

How to report

Email us. Include steps to reproduce, the impact as you see it, and how you would like to be credited if it qualifies.

security@simplesecurity.se

We acknowledge every report within 72 hours. Reports go straight into our own incident workflow — the same one the product ships to customers — so nothing sits in an inbox unread.

Hall of fame security.txt

This event runs for a limited period and closes once we are satisfied with the coverage. Responsible disclosure at security@simplesecurity.se stays open permanently, event or no event.