PEAK Wind · Security

Vulnerability Disclosure Policy


PEAK Wind takes the security of our systems and the protection of our information seriously. If you believe you have found a security vulnerability in one of our websites or services, we welcome your report and will work with you to resolve it.

Report a vulnerability

We acknowledge every report within two business days. Reports are accepted in English and Danish.

What to include in your report

  • The website, system or URL affected
  • What the vulnerability is and its potential impact
  • The steps needed to reproduce it (proof of concept, requests, or screenshots)
  • Any tools or configuration used
  • How we can reach you for follow-up

What you can expect from us

  • We will acknowledge your report within two business days.
  • We will assess it and aim to confirm the issue and its severity within five business days.
  • We will keep you informed at reasonable intervals until the issue is resolved.
  • We will handle your report confidentially and will not share your details without your permission, except where required by law.

Safe harbour

If you make a good-faith effort to comply with this policy during your research, we will consider your actions authorised, and we will not pursue or support legal action against you. If a third party takes action against you for activity carried out in line with this policy, we will make it known that your actions were authorised.

What we ask of you

  • Report any vulnerability you discover promptly, and directly to us.
  • Give us a reasonable period to investigate and fix the issue before disclosing it publicly or to any third party.
  • Only interact with accounts and systems you own or have explicit permission to test.
  • Do not access, modify, delete or download data beyond the minimum necessary to demonstrate the vulnerability.
  • Do not degrade, disrupt or deny our services — for example, no denial-of-service testing or high-volume automated scanning that affects availability.
  • Do not use social engineering (such as phishing), physical attacks, or attacks against our staff, offices or suppliers.
  • Comply with all applicable laws and respect the privacy of our users, staff and customers. If you encounter personal data, stop and report it to us — do not store, copy or share it.

Scope

This policy applies to internet-facing systems operated by PEAK Wind, including peak-wind.com and our other public websites and domains. The following are out of scope:

  • Findings that require physical access to our premises or devices
  • Denial-of-service (DoS/DDoS) and volumetric attacks
  • Social engineering of our staff, customers or suppliers
  • Output from automated tools without a demonstrable, exploitable impact
  • Best-practice suggestions with no proven security impact (for example, a missing HTTP header with no working exploit)
  • Vulnerabilities in third-party services we do not operate — please report those to the relevant provider

We value the work of the security community. If you report a valid vulnerability in line with this policy, we are happy to acknowledge your contribution on request. Last reviewed: [07/2026]