Responsible Disclosure

If you've found a security vulnerability in Cadence, please report it to privacy@updates.getcadence.uk before disclosing it publicly.

This is a disclosure program, not a bug bounty — there's no financial reward, but valid reports will be acknowledged.

Please include: what you found, steps to reproduce, and any relevant browser/device info. We'll aim to respond within 5 business days.

Out of scope: social engineering, physical attacks, already-authenticated attacks where the attacker controls their own account, and issues requiring unlikely user interaction.

Privacy Policy: /privacy-policy.html