Last updated 4 September 2026
01How to report
Email contact@prodiasystems.com with the subject line "Cloudial security". Include the affected endpoint or component, reproduction steps, the impact you believe it has, and how we can contact you.
02What we ask
- Give us a reasonable period to investigate and remediate before disclosure.
- Do not access, modify or exfiltrate data belonging to others, and do not degrade service availability.
- Do not run automated scanning or load testing against production without written authorisation.
- Stop testing immediately if you encounter personal data, and tell us.
03What we commit to
- Acknowledge your report within five working days.
- Keep you informed of triage outcome and remediation progress.
- Not pursue action against researchers who follow this policy in good faith.
- Credit you when a fix ships, if you would like to be credited.
04Out of scope
Reports without a demonstrable security impact — such as missing best-practice headers, self-inflicted browser issues, or theoretical findings from automated tools — are recorded but may not be actioned.
05No bounty programme
Prodia Systems Limited does not currently operate a paid bug-bounty programme. We will say so plainly rather than imply a reward that does not exist.