Responsible Disclosure Policy

Responsible Disclosure & Vulnerability Reporting Policy

Last updated: 14 August 2026

Security, in brief

Protecting edge+ease, our customers and their information is important to us.

We welcome responsible reports from security researchers, customers and others who believe they have identified a genuine security vulnerability affecting an edge+ease system or digital service.

This Policy explains:

  • how to report a suspected vulnerability;
  • what systems are within scope;
  • what testing is and is not permitted;
  • what information to include;
  • what you can expect from us; and
  • the limits of this Policy.

This Policy does not authorise unlawful access, harmful testing, disruption, data theft, access to another person's information or any activity that would otherwise be unlawful.

1. Who we are

This Policy applies to:
Superdivergent Ltd
trading as edge+ease
167–169 Great Portland Street
5th Floor
London
W1W 5PF
United Kingdom
Company number: 16509373

2. Purpose

Security vulnerabilities can sometimes be identified by people outside our organisation.
Responsible reporting helps us investigate and address genuine issues before they can be misused.

This Policy provides a clear framework for responsible vulnerability reporting while helping protect:

  • edge+ease customers;
  • personal and health-related information;
  • our website, app and platform;
  • our systems and infrastructure;
  • our employees and contractors;
  • our suppliers; and
  • the confidentiality, integrity and availability of our Services.

3. What this Policy covers

This Policy applies to genuine or suspected security vulnerabilities affecting systems operated by, or specifically on behalf of, Superdivergent Ltd in connection with edge+ease.
Depending on the systems currently available, this may include:

  • the edge+ease website;
  • customer accounts;
  • login and authentication;
  • the edge+ease app;
  • edge+ease APIs;
  • account and profile functionality;
  • subscription-management functionality operated by edge+ease;
  • questionnaires and check-ins;
  • self-tracking features;
  • journals or notes;
  • breathing-exercise functionality;
  • EFT (Emotional Freedom Techniques) course and content functionality;
  • course or exercise progress tracking;
  • personalised wellbeing features;
  • AI-supported features;
  • wearable and connected-service integrations;
  • edge+ease-controlled databases and cloud infrastructure;
  • customer-support functionality; and
  • other digital systems that we expressly identify as being operated by edge+ease.

Security issues may include vulnerabilities affecting:

  • confidentiality;
  • integrity;
  • availability;
  • authentication;
  • authorisation;
  • account isolation;
  • access control;
  • personal data;
  • health or wellbeing information;
  • session management;
  • application security;
  • API security; or
  • another material security control.

4. edge+ease wellbeing and course features

Some edge+ease digital features may include free educational or wellbeing content, such as:

  • guided breathing exercises;
  • EFT exercises or courses;
  • wellbeing education;
  • videos or audio;
  • prompts;
  • exercises;
  • check-ins; and
  • related educational content.

The fact that content is free to access does not authorise testing of the underlying:

  • application;
  • APIs;
  • authentication;
  • administrative interfaces;
  • databases;
  • user accounts;
  • user progress;
  • personal information; or
  • infrastructure.

A problem with the content itself is not normally a security vulnerability.
For example, the following should normally be sent to customer support rather than reported under this Policy:

  • a typo;
  • a broken content link;
  • a concern about the wording of a breathing exercise;
  • a concern about an EFT lesson;
  • a health or wellbeing content question;
  • a product-information question; or
  • a disagreement with a recommendation or educational statement.

However, an issue is relevant to this Policy if, for example, it:

  • exposes another user's course progress or personal information;
  • allows unauthorised access to another account;
  • permits modification of another person's data;
  • exposes private journal or check-in information;
  • bypasses authentication or permissions;
  • allows malicious code or content to be injected;
  • exposes administrative functionality; or
  • otherwise creates a genuine security risk.

5. Sensitive information within edge+ease

Some edge+ease features may involve particularly sensitive information, including:

  • wellbeing information;
  • questionnaire responses;
  • symptom or self-report information;
  • journal entries;
  • check-in responses;
  • wearable data;
  • generated or inferred wellbeing information; and
  • other information that may reveal aspects of physical or mental health.

You must not intentionally access another person's information in order to prove a vulnerability.
If you unexpectedly encounter personal or sensitive information, stop once you have obtained the minimum evidence reasonably necessary to report the issue.

6. Systems that are not automatically in scope

This Policy does not give you permission to test every third-party service used by edge+ease.
Unless the relevant provider expressly authorises you separately, you must not test infrastructure or services independently operated by third parties such as:

  • Shopify;
  • payment processors;
  • banks or payment networks;
  • delivery or fulfilment providers;
  • cloud platforms outside the assets we control;
  • wearable providers;
  • health-platform providers;
  • app stores;
  • video or content-hosting platforms;
  • email providers;
  • analytics providers;
  • advertising platforms;
  • social networks; or
  • other third-party suppliers.

Those organisations may have their own vulnerability-disclosure programmes.
If you believe an edge+ease integration with a third party creates a vulnerability, you may report it to us without conducting unauthorised testing of the third party.

7. How to report a vulnerability

If you believe you have identified a security vulnerability affecting edge+ease, please contact:
support@theedgeandease.com

Please use the subject line:
SECURITY VULNERABILITY

Where possible, include:

  • a clear description of the issue;
  • the affected system, page, app feature, API or asset;
  • the date and approximate time the issue was identified;
  • steps needed to reproduce it;
  • the expected behaviour;
  • what actually occurred;
  • the likely security impact;
  • whether authentication is required;
  • whether you believe personal data may be affected;
  • limited screenshots or other evidence where useful;
  • a minimal proof of concept, if genuinely necessary; and
  • your contact details if you would like a response.

Please send only the information reasonably necessary for us to understand the issue.
Do not send unnecessary copies of:

  • another user's personal information;
  • health or wellbeing information;
  • passwords;
  • authentication tokens;
  • payment information;
  • private journals;
  • wearable information; or
  • other confidential data.

Where possible, redact sensitive information before sending evidence.

8. If you accidentally access personal data

If your research unexpectedly exposes another person's personal or confidential information:

  • Stop accessing it once you have enough information to report the vulnerability.
  • Do not search for additional affected users.
  • Do not download or copy more information than is strictly necessary.
  • Do not modify or delete the information.
  • Do not disclose it to another person.
  • Do not use it for any purpose.
  • Secure any minimal evidence already obtained.
  • Report the issue to us promptly.

If appropriate, we may ask you to securely delete information inadvertently obtained during testing.
Nothing in this Policy prevents you from complying with a legal obligation that applies to you.

9. Good-faith reporting

We ask researchers to act:

  • honestly;
  • proportionately;
  • carefully;
  • in good faith; and
  • with the objective of improving security rather than exploiting a vulnerability.

You should:

  • test only accounts you own or are expressly authorised to use;
  • minimise access to systems and information;
  • avoid disrupting customers or Services;
  • stop testing once sufficient evidence exists;
  • avoid unnecessary collection of data;
  • keep vulnerability information secure;
  • report a material issue promptly; and
  • give us a reasonable opportunity to investigate before public disclosure.

If you are unsure whether proposed testing is appropriate, contact us before carrying it out.

10. Safe testing guidelines

To minimise risk, please:

  • use your own edge+ease account wherever possible;
  • use your own test information rather than another person's data;
  • keep request volumes low and proportionate;
  • avoid affecting Service performance;
  • do not create unnecessary test accounts;
  • do not attempt to obtain administrator privileges beyond what is necessary to demonstrate an issue;
  • do not access unrelated systems;
  • do not establish persistence;
  • do not retain data;
  • stop immediately if your activity begins affecting other customers; and
  • stop once you have established enough evidence to make a useful report.

You do not need to demonstrate the maximum possible impact of a vulnerability.
For example, if you establish that an authorisation weakness could expose another user's information, do not continue accessing additional user records to prove that the issue is widespread.

11. Automated security scanning

Limited, non-destructive automated scanning may be acceptable where it:

  • operates at a reasonable rate;
  • does not materially affect Service performance;
  • does not attempt denial-of-service;
  • does not bypass authentication;
  • does not access another user's information;
  • does not create excessive accounts or traffic;
  • does not repeatedly trigger notifications or communications;
  • does not incur material cost to edge+ease or our suppliers; and
  • stops if operational impact occurs.

High-volume, aggressive or disruptive scanning is not authorised.
We may block traffic, IP addresses, accounts or automated activity where reasonably necessary to protect the Services, regardless of whether the activity was intended as security research.

12. Activities that are not authorised

This Policy does not authorise:

  • accessing another user's account without permission;
  • deliberately accessing another person's personal data;
  • accessing health or wellbeing data that does not belong to you;
  • downloading or exfiltrating customer data;
  • modifying or deleting another person's information;
  • accessing private journals, check-ins or wearable data without authority;
  • accessing payment information without authority;
  • establishing persistence;
  • installing a backdoor;
  • malware deployment;
  • ransomware;
  • denial-of-service or distributed denial-of-service attacks;
  • deliberate Service degradation;
  • high-volume load or stress testing;
  • credential stuffing;
  • uncontrolled brute-force attacks;
  • password spraying;
  • phishing;
  • impersonation;
  • social engineering of employees, contractors, users or suppliers;
  • spam or bulk unsolicited communications;
  • physical security testing;
  • testing employee devices;
  • testing third-party systems without their permission;
  • bypassing security controls for a purpose unrelated to demonstrating a vulnerability;
  • exploiting a vulnerability beyond what is reasonably necessary to confirm it;
  • using a vulnerability for commercial leverage;
  • extortion;
  • threatening disclosure in exchange for money;
  • selling vulnerability information to a malicious party;
  • destruction or alteration of data;
  • public disclosure that creates an avoidable immediate risk to users; or
  • any activity that violates applicable law.

13. Low-impact or non-security reports

We welcome useful feedback, but some issues may not represent a security vulnerability.
Examples may include:

  • purely cosmetic issues;
  • spelling or grammar errors;
  • broken links with no security impact;
  • content concerns;
  • general customer-support requests;
  • health or wellbeing content questions;
  • issues requiring an obsolete or unsupported browser with no realistic impact;
  • theoretical vulnerabilities without a plausible security consequence; or
  • general security best-practice suggestions without a material vulnerability.

We may still consider such feedback, but it may be handled outside this vulnerability process or given a lower priority.

14. What we ask you not to do with a vulnerability

Before publicly disclosing a vulnerability, please give us a reasonable opportunity to:

  • validate it;
  • investigate it;
  • understand its impact;
  • protect affected users;
  • develop a fix; and
  • test remediation.

Please do not:

  • publish working exploit code prematurely;
  • publish personal data;
  • publish confidential edge+ease information;
  • share a vulnerability with parties who may misuse it;
  • demonstrate the vulnerability against additional users;
  • disclose authentication credentials or tokens;
  • contact affected edge+ease customers directly;
  • make public claims about the scale of an issue that you have not verified; or
  • demand compensation as a condition of withholding disclosure.

We encourage coordinated disclosure.
The appropriate disclosure period will depend on the severity and complexity of the issue.

15. What you can expect from us

When we receive a credible report, we aim to:

  • acknowledge receipt within a reasonable period;
  • review the information provided;
  • assess the potential severity;
  • route it to the appropriate technical owner;
  • involve a relevant supplier where necessary;
  • investigate proportionately;
  • take reasonable steps to address confirmed vulnerabilities;
  • keep the reporter informed where practical; and
  • coordinate any appropriate disclosure.

We may ask for additional information where necessary to:

  • reproduce the issue;
  • understand its impact; or
  • confirm remediation.

Response and remediation time will depend on factors including:

  • severity;
  • exploitability;
  • customer impact;
  • complexity;
  • supplier involvement;
  • availability of a fix;
  • testing requirements; and
  • competing security priorities.

We do not guarantee:

  • a particular response time;
  • a particular remediation deadline;
  • that every report will result in a change;
  • detailed disclosure of our infrastructure;
  • access to internal investigations; or
  • public acknowledgement of a reporter.

16. Personal data breaches

A vulnerability does not automatically mean that a personal data breach has occurred.
Where a report indicates that personal data may have been:

  • accessed;
  • disclosed;
  • lost;
  • altered;
  • destroyed; or
  • otherwise compromised,

edge+ease will assess the issue under our internal data-breach and incident-response procedures.
Where required by applicable law, Superdivergent Ltd will determine and make any required notification to regulators or affected individuals.
Researchers should not contact affected customers directly unless legally required to do so.

17. Reports affecting third-party providers

Some parts of edge+ease depend on third-party services.
If a reported vulnerability appears to involve one of our suppliers, we may:

  • share relevant information with the supplier;
  • involve the supplier in our investigation;
  • ask the supplier to investigate;
  • refer the report to the supplier; or
  • ask you to contact the supplier through its own responsible-disclosure process.

We will aim to share only the information reasonably necessary to investigate or remediate the issue.

18. Public disclosure

We encourage responsible and coordinated disclosure.
If you want to publish research relating to an edge+ease vulnerability, please contact us first so that we can discuss an appropriate timeline.
We may ask you to delay publication where reasonably necessary to:

  • remediate the vulnerability;
  • protect customers;
  • coordinate a supplier fix;
  • investigate wider exposure; or
  • comply with legal or regulatory requirements.

Nothing in this Policy requires a person to withhold information where disclosure is required by law.

19. Compensation and bug bounties

Submitting a vulnerability report does not create any entitlement to:

  • payment;
  • a bug bounty;
  • reimbursement;
  • compensation;
  • employment;
  • a commercial relationship;
  • free Products or Services; or
  • public recognition.

edge+ease does not operate a bug-bounty programme unless we expressly announce one in writing.
We may choose to recognise or thank a reporter at our discretion.
Do not incur costs on the assumption that Superdivergent Ltd will reimburse them.

20. Legal position and limits of this Policy

This Policy is intended to encourage responsible vulnerability reporting.
It does not:

  • create blanket permission to access edge+ease systems;
  • authorise conduct that would otherwise be unlawful;
  • authorise testing outside the scope of this Policy;
  • create a contractual right to conduct security testing;
  • waive any legal rights or remedies available to Superdivergent Ltd;
  • prevent us from protecting our Services;
  • prevent us from blocking accounts, traffic or activity presenting a security risk;
  • limit our ability to investigate suspected unlawful activity; or
  • prevent us from referring suspected unlawful activity to an appropriate authority.

When assessing conduct, we may take into account matters including:

  • whether the person acted genuinely and in good faith;
  • whether testing was proportionate;
  • whether unnecessary information was accessed;
  • whether the activity caused harm or disruption;
  • whether the person stopped once sufficient evidence existed;
  • whether the vulnerability was reported promptly; and
  • whether the person otherwise followed this Policy.

Superdivergent Ltd reserves its legal rights.

21. Employee and contractor obligations

Employees, contractors and other people working for edge+ease must report suspected vulnerabilities through the appropriate internal process.
They must not:

  • conceal security issues;
  • unnecessarily access affected information;
  • disclose vulnerability details externally without authority; or
  • investigate in a way that creates additional risk.

A vulnerability involving personal data must also be considered under our internal data-breach procedures.

22. Security and privacy

Security reports themselves may contain:

  • personal data;
  • researcher contact details;
  • IP addresses;
  • screenshots;
  • system information; or
  • sensitive technical material.

We handle this information in accordance with applicable data-protection law, our Privacy Policy and our internal security procedures.
We ask reporters to minimise personal data contained in reports.

No technology or security programme can guarantee that a system will be completely free from vulnerabilities.
The existence of this Policy does not constitute a warranty that edge+ease systems or Services are free from security defects.

23. Changes to this Policy

We may update this Policy to reflect changes to:

  • the edge+ease website;
  • the app or platform;
  • breathing or EFT content functionality;
  • AI-supported functionality;
  • wearable integrations;
  • our systems or suppliers;
  • security risks;
  • our internal processes; or
  • applicable legal or regulatory requirements.

The latest version will show the date it was last updated.

24. Contact us

For vulnerability reports or questions about this Policy, contact:
Superdivergent Ltd
trading as edge+ease
167–169 Great Portland Street
5th Floor
London
W1W 5PF
United Kingdom
Company number: 16509373
Email: support@theedgeandease.com

For vulnerability reports, please use the email subject:
SECURITY VULNERABILITY