Skip to content
Upinity Upinity
Features AI Intelligence Pricing
Italiano English Deutsch Français Español Português
Start Free Trial

Home → Security Policy

Security Policy

Last updated: 22 May 2026

We welcome reports from security researchers. This page describes how to report a vulnerability and what to expect from our response. The machine-readable equivalent following RFC 9116 is at /.well-known/security.txt.

Contents

  1. How to Report
  2. Scope
  3. Response Times
  4. Recognition
  5. Compliance
  6. Safe Harbour

How to Report

Email security@upinity.com with: a description of the vulnerability, the affected endpoint or component, reproduction steps, and (if applicable) a proof-of-concept. Please do not post vulnerabilities publicly before we've had a chance to acknowledge and fix them.

Scope

In scope: upinity.com (marketing site), app.upinity.com (SaaS application), go.powerb.swiss (Mautic instance handling our forms). Out of scope: social engineering or phishing of POWERB staff, denial-of-service or volumetric attacks, vulnerabilities in third-party services we depend on (Stripe, hosting providers — please report directly to them).

Response Times

We acknowledge new reports within 2 business days. Initial assessment and severity classification within 5 business days. Fix or mitigation timeline depends on severity and is communicated in our acknowledgement reply.

Recognition

We don't currently operate a paid bug bounty programme. Researchers who report valid vulnerabilities responsibly are credited on a public hall of fame (with their consent) and receive a written acknowledgement letter.

Compliance

We aim for alignment with SOC 2 controls and ISO 27001 practices. GDPR / Swiss nLPD compliance is detailed in our Privacy Policy. Specific compliance certificates can be requested from sales@upinity.com under NDA.

Safe Harbour

We will not pursue legal action against researchers who follow this policy, act in good faith, do not access or modify data beyond what is necessary to demonstrate the vulnerability, and do not impact availability of the service.

Security contact: security@upinity.com. Public PGP key: not currently published; we accept reports in plain email and will move to encrypted channels if requested.

Related

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
Product
  • Features
  • Pricing
Company
  • About Us
  • Contact
Legal
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Security Policy
  • Matrix Intelligence
Stay Updated

Get the latest monitoring and security insights

© 2026 Upinity. All rights reserved. — POWERB SAGL