Exposia
Pricing About
Français
Sign in Sign up

Responsible vulnerability disclosure

Service Exposia — https://app.exposia.ca

We encourage responsible reporting of security issues regarding this site and the services available on it. This document specifies what we expect from researchers and how to contact us.

How to report a vulnerability

Send a detailed email to the official address: security@certi360.com. Include, when possible:

  • a description of the issue and its potential impact;
  • steps to reproduce the discovery;
  • the approximate date and time of your tests;
  • your means of contact for technical details.

You can encrypt your message with the public PGP key published at https://app.exposia.ca/.well-known/pgp-key.txt (referenced from the file security.txt).

What we ask

  • Act in good faith : Act in good faith: aim to inform us without harming users or the service.
  • Do not disrupt availability : Do not disrupt availability: avoid load testing, denials of service and any action that could degrade or interrupt service.
  • Respect the privacy of others : Respect the privacy of others: do not access account data that is not yours; do not view, copy or retain personal data beyond what is strictly necessary to demonstrate the problem.
  • Do not exploit more than necessary : Do not exploit more than necessary: limit yourself to what establishes the existence and seriousness of the problem.
  • Report confidentiality : Report Confidentiality: Do not publicly disclose the vulnerability until a reasonable patch has been deployed, unless we agree otherwise.

Correction time

We strive to acknowledge receipt within a reasonable time and treat serious reports as a priority. We ask that you give us a reasonable period of time (often around 90 days, depending on the complexity) before any public disclosure, unless there is a legal obligation or imminent risk requiring more rapid communication.

After reporting

Responsible reports are appreciated. Depending on the circumstances, public recognition may be offered; see the Acknowledgments. No compensation is guaranteed for simply disclosing a vulnerability (we do not promise a formal bug bounty program in this document).


English (summary): Report security issues responsibly to security@certi360.com. Do not perform DoS testing, do not access others’ data, allow reasonable time for fixes before public disclosure, and use the PGP key linked from our security.txt if you wish to encrypt your message.

© 2026 Exposia — Hosted in Canada

Product brought to you by Certi360

Sign in · Create an account · Features · Pricing

FAQ · About · Changelog · Help · Privacy Policy · Terms of Use