How do I report a security issue to TechSteps?

Email [email protected] with the affected URL or host, what you found, and enough detail to reproduce it. Please do not open a public issue or post it publicly before we have had a chance to fix it. We will acknowledge within three working days and keep you informed until it is resolved.

In scope

  • techsteps.ae and its subdomains
  • secai.techsteps.ae
  • stackattest.com

Client systems are not in scope. If you believe you have found an issue in a system we operate for a client, tell us and we will route it to the right owner. Do not test a client system without that client's authorization.

What we ask

  • Give us a reasonable window to fix the issue before disclosing it publicly.
  • Use the minimum access needed to demonstrate the problem. Do not read, modify or exfiltrate data belonging to anyone else.
  • Do not run denial of service tests, spam, or social engineering against our staff.
  • Do not use automated scanners at a volume that degrades service for other users.

What we commit to

  • We acknowledge reports within three working days.
  • We tell you our assessment of severity and our intended timeline.
  • We keep you updated until the issue is closed.
  • We will not pursue legal action against anyone who reports in good faith and follows the guidance above.
  • We are happy to credit you publicly once the fix is deployed, if you would like that.

We do not currently run a paid bug bounty. We will say so honestly rather than imply a reward that does not exist.

Security posture of this website

This site is a static build. There is no application server, no database and no user authentication behind it, which removes most of the attack surface a marketing site usually carries.

  • Served over HTTPS.
  • Third-party JavaScript is kept to a minimum. The only third-party script is Google Analytics, and it is loaded only for visitors who accept it. Decline and nothing external is requested.
  • Fonts are self-hosted, so rendering the page requires no third-party request.
  • No secrets or credentials are present in anything sent to the browser.
  • Security response headers including HSTS, a content security policy, frame restrictions, X-Content-Type-Options, Referrer-Policy and Permissions-Policy are applied at the edge. See contact us if you need the current header set for a vendor review.

How we handle security in client work

Two commitments that matter more than a list of tools.

Access is scoped and time-bounded. We ask for the least access that lets us do the work, we use named accounts rather than shared credentials, and we tell you when we no longer need access so it can be revoked.

Automated action has a boundary. In our own security product, blocking a hostile IP address can happen automatically. Restarting services, rotating credentials, changing accounts and installing packages require human approval. We apply the same principle to client systems: automation handles the reversible, humans decide the rest.

Reporting something urgent

If you are a client dealing with an active incident rather than reporting a vulnerability, call +971 50 397 5374 rather than emailing. Say what is happening and what has already been changed.