The process

The process consists of the following steps:

  • Discovery — security researchers or ethical hackers identify a vulnerability.
  • Reporting — researchers should submit a detailed report about the vulnerability, including a comprehensive description with technical details, steps to reproduce it (proof of concept), the specific system, domain or application affected, and optionally a suggestion for a potential solution.
  • Verification — we acknowledge the report, review the vulnerability, and verify its existence.
  • Remediation — we work on developing a patch or fix to address the vulnerability.
  • Recognition — after reporting and verification, we acknowledge the researcher's contribution based on an assessment.

Reports can be submitted by sending an email to .

How contributions are assessed

Recognition is based on an assessment that considers:

  • Vulnerability impact — the potential severity of the vulnerability and the damage it could cause.
  • Vulnerability size — the scope of the vulnerability and the number of systems or users it affects.
  • Cooperation — the researcher's communication style, willingness to work with us, and adherence to responsible disclosure practices.
  • Solution provided — whether the researcher included a potential solution or workaround in their report.

Forms of recognition

Following evaluation, recognition will be granted, potentially taking various forms:

  • Social media acknowledgement — publicly recognizing the researcher's contribution on our social media platforms.
  • Reward.
  • Certificate of appreciation — awarding a certificate to acknowledge the researcher's role in improving our security.
  • Working with the researcher as a consultant — it is possible to engage the researcher to work with our company as a consultant on security vulnerabilities and technical issues.

Recognition is not guaranteed for all reported vulnerabilities. We reserve the right to not publicly acknowledge or reward vulnerabilities.

The objective of the policy

The Vulnerability Responsible Reporting policy helps protect our users and systems from potential attacks. It fosters collaboration between security researchers and us, creating a more secure digital environment for everyone. By implementing this recognition system, we aim to incentivize responsible reporting and express gratitude to security researchers who help us maintain a vulnerability-free system.

For any information or inquiries, please contact us at .