Responsible Vulnerability Disclosure
Last updated: August 2026
1. Our commitment
At DITAP we take the security of our site, our products and the infrastructure we operate for our clients seriously. If you found a security vulnerability, we want to know before anyone else does — and we value the work of anyone who tells us in good faith.
This page describes how to report a finding to us, what is in and out of scope, and what you can expect from us in return.
2. How to report
Email [email protected] with the subject "[SECURITY] short description". We don't currently run a public bug bounty program or intake form — this is a direct line to our technical team.
Please include, as far as possible:
Please don't disclose the finding publicly (social media, forums, mailing lists) before we've coordinated a disclosure timeline with you.
3. Scope
In scope:
Out of scope:
4. Safe harbor for good-faith researchers
If your research is conducted in good faith, within the scope defined above, and without accessing, modifying or exfiltrating data beyond what is strictly necessary to demonstrate the vulnerability:
This safe harbor doesn't cover testing that violates applicable law, accesses third-party data beyond what's needed for proof of concept, or is conducted against systems outside the scope defined in Section 3.
5. What you can expect from us
| Stage | Reference timeframe |
|---|---|
| Acknowledgment of your report | 3 business days |
| Initial severity and impact assessment | 10 business days |
| Status update (while resolving) | Every 15 business days at most |
| Remediation of critical findings | Immediate priority, no fixed public deadline for operational security reasons |
We don't currently offer a paid bug bounty for reports. If the finding is valid and actionable, we're happy to credit you publicly (with your consent) once it's resolved.
6. Contact
Email: [email protected] (subject "[SECURITY] ...")
Phone / WhatsApp: +39 345 243 5103
Policy published at: https://www.ditap.io/en/security/disclosure
Referenced from: /.well-known/security.txt, per RFC 9116.