Skip to content
Ditap®
Back to Home

Responsible Vulnerability Disclosure

Last updated: August 2026

1. Our commitment

At DITAP we take the security of our site, our products and the infrastructure we operate for our clients seriously. If you found a security vulnerability, we want to know before anyone else does — and we value the work of anyone who tells us in good faith.

This page describes how to report a finding to us, what is in and out of scope, and what you can expect from us in return.

2. How to report

Email [email protected] with the subject "[SECURITY] short description". We don't currently run a public bug bounty program or intake form — this is a direct line to our technical team.

Please include, as far as possible:

  • The affected URL or system.
  • Steps to reproduce the issue (proof of concept).
  • Potential impact, as you assess it.
  • Your contact information, if you'd like credit or to be kept informed of progress.
  • Please don't disclose the finding publicly (social media, forums, mailing lists) before we've coordinated a disclosure timeline with you.

    3. Scope

    In scope:

  • The ditap.io site and its subdomains directly operated by DITAP.
  • The serverless functions and proprietary APIs serving the site (contact, checkout, newsletter, ebook delivery).
  • The status page at /status and its source (app.ditap.io/api/status), as a system exposed by DITAP.
  • Out of scope:

  • Our sub-processors' systems (Vercel, Supabase, Cloudflare, Stripe, MercadoPago, Resend, Google Analytics, Sentry) — please report directly to the relevant vendor. See detail at /trust/sub-processors.
  • Denial-of-service attacks (DoS/DDoS), mass brute-forcing, or any test that degrades the service for other users.
  • Social engineering, phishing, or physical attacks against employees, clients or facilities.
  • Findings that require physical access to a DITAP client's device or network without their explicit authorization.
  • Vulnerabilities in outdated software versions controlled by the user (e.g., an unpatched browser).
  • 4. Safe harbor for good-faith researchers

    If your research is conducted in good faith, within the scope defined above, and without accessing, modifying or exfiltrating data beyond what is strictly necessary to demonstrate the vulnerability:

  • We won't initiate or recommend legal action against you for that report.
  • We'll treat your report as confidential and won't share your identity without your consent, unless legally required.
  • We'll keep you informed of progress to the extent the nature of the finding allows.
  • This safe harbor doesn't cover testing that violates applicable law, accesses third-party data beyond what's needed for proof of concept, or is conducted against systems outside the scope defined in Section 3.

    5. What you can expect from us

    StageReference timeframe
    Acknowledgment of your report3 business days
    Initial severity and impact assessment10 business days
    Status update (while resolving)Every 15 business days at most
    Remediation of critical findingsImmediate priority, no fixed public deadline for operational security reasons

    We don't currently offer a paid bug bounty for reports. If the finding is valid and actionable, we're happy to credit you publicly (with your consent) once it's resolved.

    6. Contact

    Email: [email protected] (subject "[SECURITY] ...")

    Phone / WhatsApp: +39 345 243 5103

    Policy published at: https://www.ditap.io/en/security/disclosure

    Referenced from: /.well-known/security.txt, per RFC 9116.