Skip to Content

TRUST

Responsible Disclosure Policy

How to report a vulnerability in our website or services, and what we commit to in return.

Our commitment

We welcome reports from security researchers. If you report a vulnerability in good faith and follow this policy, we will not pursue or support legal action against you, and we will work with you until the issue is resolved.

In scope

  • defynia.us and its subdomains.
  • Public services operated by Defynia under its own domains.

Out of scope

  • Systems belonging to our customers or to the manufacturers we represent.
  • Denial of service, volumetric or load testing.
  • Social engineering of our staff, customers or suppliers, and physical intrusion.
  • Reports generated only by an automated scanner, with no demonstrated impact.

How to report

Send to info@defynia.us with the subject line "Security report": a description of the issue, the steps to reproduce it, the affected URL or component, and the impact you were able to demonstrate. Please do not disclose it publicly until we have confirmed a fix.

What you can expect from us

  • Acknowledgment of your report within 2 business days.
  • Initial assessment and severity within 5 business days.
  • A status update every 10 business days while we work on it.
  • Public credit on resolution, if you want it.

We do not currently operate a paid bug bounty program.

Rules

Access only the data strictly necessary to demonstrate the issue, never modify or delete data, and delete any data you obtained once your report is submitted.