Responsible Disclosure
If you've found a security vulnerability in Cadence, please report it to privacy@updates.getcadence.uk before disclosing it publicly.
This is a disclosure program, not a bug bounty — there's no financial reward, but valid reports will be acknowledged.
Please include: what you found, steps to reproduce, and any relevant browser/device info. We'll aim to respond within 5 business days.
Out of scope: social engineering, physical attacks, already-authenticated attacks where the attacker controls their own account, and issues requiring unlikely user interaction.
Privacy Policy: /privacy-policy.html