Vulnerability Disclosure Policy
PEAK Wind takes the security of our systems and the protection of our information seriously. If you believe you have found a security vulnerability in one of our websites or services, we welcome your report and will work with you to resolve it.
We acknowledge every report within two business days. Reports are accepted in English and Danish.
What to include in your report
- The website, system or URL affected
- What the vulnerability is and its potential impact
- The steps needed to reproduce it (proof of concept, requests, or screenshots)
- Any tools or configuration used
- How we can reach you for follow-up
What you can expect from us
- We will acknowledge your report within two business days.
- We will assess it and aim to confirm the issue and its severity within five business days.
- We will keep you informed at reasonable intervals until the issue is resolved.
- We will handle your report confidentially and will not share your details without your permission, except where required by law.
Safe harbour
If you make a good-faith effort to comply with this policy during your research, we will consider your actions authorised, and we will not pursue or support legal action against you. If a third party takes action against you for activity carried out in line with this policy, we will make it known that your actions were authorised.
What we ask of you
- Report any vulnerability you discover promptly, and directly to us.
- Give us a reasonable period to investigate and fix the issue before disclosing it publicly or to any third party.
- Only interact with accounts and systems you own or have explicit permission to test.
- Do not access, modify, delete or download data beyond the minimum necessary to demonstrate the vulnerability.
- Do not degrade, disrupt or deny our services — for example, no denial-of-service testing or high-volume automated scanning that affects availability.
- Do not use social engineering (such as phishing), physical attacks, or attacks against our staff, offices or suppliers.
- Comply with all applicable laws and respect the privacy of our users, staff and customers. If you encounter personal data, stop and report it to us — do not store, copy or share it.
Scope
This policy applies to internet-facing systems operated by PEAK Wind, including peak-wind.com and our other public websites and domains. The following are out of scope:
- Findings that require physical access to our premises or devices
- Denial-of-service (DoS/DDoS) and volumetric attacks
- Social engineering of our staff, customers or suppliers
- Output from automated tools without a demonstrable, exploitable impact
- Best-practice suggestions with no proven security impact (for example, a missing HTTP header with no working exploit)
- Vulnerabilities in third-party services we do not operate — please report those to the relevant provider
We value the work of the security community. If you report a valid vulnerability in line with this policy, we are happy to acknowledge your contribution on request. Last reviewed: [07/2026]