Effective: January 22, 2026
At SPEKMI, we take security seriously. We appreciate the work of security researchers and the broader security community in helping us maintain the security of our platform and protect our users. This policy outlines how to report security vulnerabilities responsibly.
Security is a core priority at SPEKMI. We are committed to:
The following assets and services are covered by this policy:
spekmi.com - Main websiteapp.spekmi.com - Application platformapi.spekmi.com - API endpointsThe following are explicitly out of scope:
If you believe you have discovered a security vulnerability, please report it to us by email:
Security Contact
security@spekmi.comPlease include the following information in your report:
We accept vulnerability reports in English or French.
When you report a vulnerability to us in good faith, we commit to:
Acknowledge your report within 5 business days
Keep you informed of our progress throughout the process
Not pursue legal action against good-faith security researchers
Credit you for your discovery (with your consent) after remediation
To ensure your research is conducted responsibly and within legal boundaries, please follow these guidelines:
Do report vulnerabilities as soon as possible after discovery
Do provide sufficient detail for us to reproduce and understand the issue
Do use test accounts you control when testing
Do allow reasonable time for remediation before disclosure
Don't access, modify, or delete other users' data
Don't disrupt service availability or degrade user experience
Don't share vulnerability details publicly before we've had time to fix them
Don't use automated scanners that generate excessive traffic
Don't attempt to exfiltrate any data beyond what is necessary to demonstrate the vulnerability
When you submit a vulnerability report, we will collect and process your personal data (such as your name, email address, and any other information you provide) to:
Your personal data will be processed in accordance with our Privacy Policy. We will not share your personal information with third parties without your consent, except as required by law.
If you conduct security research in good faith and in accordance with this policy, we consider your research to be:
We will not initiate legal action against you or report you to law enforcement for security research conducted in compliance with this policy.
For security-related inquiries or to report a vulnerability:
SPEKMI Security Team
Email: security@spekmi.com
SPEKMI by BSCG
90 rue de Rivoli
75004 Paris, France