Report a security issue
No system is completely secure. If you notice something wrong in MainFoundry — or you have found a vulnerability — we want to hear about it, as early as possible.
Last reviewed: September 2026
Write to
security@mainfoundry.comWe confirm receipt within two business days and give you an initial assessment within ten.
If email is not an option, or the matter is urgent, call +45 60 53 25 27.
Monitored on business days. Danish or English. Anonymous reports are welcome.
Who this page is for
- You use MainFoundry and saw something suspicious
- An unexpected sign-in alert, data that is not yours, a change nobody made, an email that imitates us. Write to us — and change your password and revoke any sessions or tokens you do not recognise.
- You are a security researcher and found a vulnerability
- Report it to the same address. Give us the detail you would want yourself, and we will work with you on a fix and on how and when it is disclosed.
Partners, suppliers and anyone else who notices something are welcome to use the same address. MainFoundry employees and contractors report through the internal procedure, not this page.
Report first. Details can wait.
You do not need to be sure that something is an incident. Report what you saw as soon as you can — we assess it, classify it and decide what it is. Speed matters more than a complete report.
- Security event
- Something observed that could affect the confidentiality, integrity or availability of information or a system. Many events turn out to be harmless.
- Security incident
- One or more events that are likely to compromise information or business operations. Every incident starts as an event.
- Personal data breach
- A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
What to report
Anything on this list — and anything that feels like it belongs on it.
- A security measure that does not seem to work
- Single sign-on that can be bypassed, permissions that do not apply, a restriction you can get around.
- Data you should not be able to see, or data that has changed
- Records from another organisation, data that looks altered or is missing, a service that is unavailable or behaving abnormally.
- A mistake
- Yours or a colleague's — data sent to the wrong recipient, a document shared with the wrong organisation, an agent given access it should not have.
- A lost or stolen device
- A laptop or phone that is signed in to MainFoundry, or that holds a session or a token.
- Changes nobody made
- New users, altered integrations, changed permissions or configuration that no one in your organisation recognises.
- The system doing something it should not
- Especially around sign-in, permissions, approvals or data.
- Suspicious access
- Sign-in alerts you did not trigger, unknown sessions, or someone using an account that is not theirs.
- A vulnerability
- A weakness you have found in a MainFoundry website, app, API or integration.
- Phishing or malware
- Emails or sites imitating MainFoundry, or a suspected malicious file or link connected to us.
- Something that breaks a requirement you rely on
- A term in your agreement with us, or a security requirement your own compliance depends on.
When in doubt, report it. We decide whether it is an incident.
What to include
As much of this as you have. A short report now beats a complete one tomorrow.
- What you observed, in your own words
- When — date, time and time zone
- Where — the URL, module, organisation and user involved
- How you noticed it
- The impact you have seen so far
- Evidence — screenshots, the original email, log excerpts. Keep the originals unchanged.
- Whether personal data appears to be involved
- How we can reach you — or that you prefer to stay anonymous
Please do not
These rules protect our customers' data, the evidence — and you.
- Try to prove or exploit a suspected vulnerability. Report it and stop.
- Use accounts that are not your own, or access more data than you need to notice the issue.
- Continue if you encounter personal or customer data. Stop, and tell us what you saw.
- Modify, download or delete data that is not yours.
- Run denial-of-service or load tests, or attempt social engineering, phishing or physical access.
- Demand payment or make the report conditional.
- Share the issue publicly before we have responded and agreed on a timeline.
If you follow these guidelines and stay within the systems listed under Scope, we consider your research authorised and conducted in good faith. We will not pursue legal action against you for good-faith research done this way, and if a third party does, we will make it known that you acted in accordance with this page.
What happens next
Every report follows the same path, whether it comes from a customer, a researcher or our own monitoring.
- Received and logged
Your report gets a reference and a timestamp. If we can reach you, we confirm receipt within two business days.
- Assessed and classified
We decide whether it is an incident, how severe it is, and whether personal data is involved. You get our initial assessment within ten business days.
- Contained and resolved
We limit the damage first, then fix the cause. Evidence is preserved throughout.
- Customers notified
Customers whose data or service is affected hear from us directly. Authorities are informed where the law requires it.
- Closed, with feedback
We tell you the outcome, to the extent we can.
- Lessons applied
Every incident is traced to its root cause and used to improve our controls, so it is less likely to happen again.
If you are a customer: how we notify you
For the data in your MainFoundry organisation, you are the controller and MainFoundry is the processor. That shapes who does what when something goes wrong.
If we become aware of a personal data breach affecting your data, we notify you without undue delay — we do not wait to finish assessing the risk before telling you. Every affected customer is notified individually.
The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Where we do not have everything at once, we send what we have and follow up in phases.
We help you meet your own obligations: a timeline, extracts of the affected data, and relevant logs on request. We also support your notification to the Danish Data Protection Agency (Datatilsynet), which you as controller must file without undue delay and, where feasible, within 72 hours of becoming aware of the breach — unless it is unlikely to pose a risk to the people concerned.
For incidents that affect the availability or integrity of the service without involving personal data, we inform affected customers without undue delay as well.
If your own personal data is affected and you are not a MainFoundry customer, contact the organisation that uses MainFoundry — they are responsible for your data and for informing you where the law requires it. Datatilsynet explains your options as an affected individual: Affected by a breach? (Datatilsynet)
Scope, disclosure and credit
In scope
- www.mainfoundry.com
- app.mainfoundry.com
- api.mainfoundry.com
Out of scope
- Services we integrate with — Microsoft, Google, e-conomic, Stripe. Report those to the provider directly.
- Systems owned by our customers.
- Findings without a demonstrated security impact: missing headers, cookie flags, self-XSS, clickjacking on non-sensitive pages, automated scanner output, email or DNS best-practice notes.
- Denial of service in any form.
Please give us 90 days from your report before disclosing publicly, and keep the details confidential until a fix is in place and we have agreed on the timing.
We do not run a bug bounty and do not pay for reports. We credit reporters on request once the issue is resolved.
Your report and your identity are shared strictly on a need-to-know basis. We may keep your report and the related logs as evidence for as long as the incident requires. We do not pass your personal data to third parties without your permission unless the law requires it.
How this fits our security work
This page is the public part of MainFoundry's incident reporting procedure. The procedure is designed in line with ISO/IEC 27001:2022 Annex A controls 5.24–5.28 and 6.8 — the controls covering incident management planning, assessment, response, learning, evidence and event reporting. MainFoundry is working toward ISO/IEC 27001 certification and does not claim it today.
Internal reference: 5.2 Incident reportingVersion 1.0Last reviewed: September 2026Owner: Security lead Questions about this page: security@mainfoundry.com
