We encourage responsible reporting of security issues regarding this site and the services available on it. This document specifies what we expect from researchers and how to contact us.
Send a detailed email to the official address: security@certi360.com. Include, when possible:
You can encrypt your message with the public PGP key published at https://app.exposia.ca/.well-known/pgp-key.txt (referenced from the file security.txt).
We strive to acknowledge receipt within a reasonable time and treat serious reports as a priority. We ask that you give us a reasonable period of time (often around 90 days, depending on the complexity) before any public disclosure, unless there is a legal obligation or imminent risk requiring more rapid communication.
Responsible reports are appreciated. Depending on the circumstances, public recognition may be offered; see the Acknowledgments. No compensation is guaranteed for simply disclosing a vulnerability (we do not promise a formal bug bounty program in this document).
English (summary): Report security issues responsibly to security@certi360.com. Do not perform DoS testing, do not access others’ data, allow reasonable time for fixes before public disclosure, and use the PGP key linked from our security.txt if you wish to encrypt your message.