Save 50% on your first bill

NewLedger · Security

Vulnerability Disclosure Notice

Any researcher can responsibly share suspected security findings with NewLedger. We welcome good-faith reports, whether or not you are a customer. We do not run a paid bug bounty program. No prize money, cash rewards, or bounties are offered, and submitting a report does not create a right to payment or reimbursement.

Last Updated: 10 October 2026

1. Report a Suspected Issue Privately

You do not need an invitation, a NewLedger account, or prior approval to send us a report about an issue you have observed.

Email security@newledger.io with the affected URL or service, what you observed, the date, and enough redacted detail for us to understand the issue. Use synthetic examples. Keep passwords, access tokens, personal information, and customer records out of email; ask for a secure channel if sensitive evidence is needed.

2. Reporting Does Not Authorise Testing

You may report a vulnerability you have already discovered without requesting testing authorisation. This notice covers NewLedger-operated websites and services. Neither this notice nor the security email address grants permission to scan, probe, or actively test NewLedger. Obtain express written authorisation from NewLedger before active testing. Having an account or trial does not provide that authorisation. Customer-managed deployments and independently operated third-party services require separate authorisation from their respective operators.

3. Protect Accounts, Data, and Availability

Do not access other users’ accounts, download their records, change live accounting data, or disrupt service. Do not use credential attacks, social engineering, malware, persistence, destructive methods, denial-of-service, or high-volume automated scanning. If you encounter non-public data or affect service availability, stop and contact us privately. Do not continue to demonstrate further impact.

4. No Financial Rewards

NewLedger does not operate a paid bug bounty program. Submitting a report does not establish any entitlement to payment, reimbursement, recognition, employment, or commercial engagement. We assess report validity, severity, remediation priority, and any voluntary non-monetary recognition at our discretion.

5. Coordinate Disclosure

Please share findings privately first and give us a reasonable opportunity to investigate and address the issue before publishing technical details. We ask researchers to coordinate disclosure timing with us and keep credentials, personal information, and customer data private. Submitting a report does not authorise unlawful activity or limit NewLedger’s legal rights. This notice does not provide a safe harbour or promise that NewLedger will refrain from legal action. Applicable law, third-party rights, and existing agreements continue to apply; nothing here limits legally protected or required disclosures or reporting to competent authorities.