Vulnerability Disclosure Policy

We ask others to publish a disclosure policy, so here is ours. If you have found a vulnerability in this website, tell us: we do not pursue researchers who act within this Policy.

1.Scope

1.1

This Policy applies to research into the security of the systems of Osaühing Ida Portal (the “Operator”, “we”) listed in this section.

1.2

In scope are:

  1. (a)the website securitytest.team and its pages in all languages;
  2. (b)the interface that receives the requests of the form: https://securitytest.team/api/leads.

1.3

Out of scope are:

  1. (a)the systems of our clients. They are never covered by this Policy, whatever you know about our work for them;
  2. (b)the services of third parties that the website uses, including the hosting platform and the abuse check. Vulnerabilities in them are reported to their operators;
  3. (c)the accounts of our personnel on any platform, and our personnel themselves.

2.Rules of research

2.1

A researcher who acts under this Policy:

  1. (a)examines only what is in scope;
  2. (b)does not degrade the service: carries out no denial-of-service attacks, does not flood the forms and does not scan at a rate that affects availability;
  3. (c)does not use social engineering, phishing or physical access;
  4. (d)does not read, alter or keep data that does not belong to the researcher. A researcher who has obtained access to such data stops, does not copy the data and reports at once;
  5. (e)uses the least action that proves the vulnerability;
  6. (f)gives us a reasonable time to remedy the vulnerability before disclosing it to anyone else;
  7. (g)complies with the law that applies to the researcher.

3.Safe harbour

3.1

As the holder of the rights in the systems listed in Section 1, we authorise research of those systems that is carried out in good faith and in accordance with this Policy. The authorisation covers only those systems and only the actions this Policy permits.

3.2

For such research we do not file a criminal complaint and do not bring civil claims against the researcher, including claims under our Terms of Use. If a public authority or anyone else asks, we confirm that the research was authorised by us.

3.3

These undertakings are ours alone. They do not bind public authorities, do not cover the systems and the services of third parties, including the providers the website uses such as Cloudflare, Inc., and do not replace the law of another State that applies to the researcher. A researcher who doubts whether an action is within this Policy asks before acting.

4.How to report

4.1

A report is sent to info@securitytest.team. Do not include the details that allow the vulnerability to be exploited in the first message: we reply with a secure channel for them.

4.2

A useful report contains:

  1. (a)the address and the parameter or the component concerned;
  2. (b)the steps to reproduce the vulnerability from a clean state;
  3. (c)what an attacker could achieve;
  4. (d)the researcher’s own assessment of the severity, if there is one.

4.3

The machine-readable version of our contacts is published at https://securitytest.team/.well-known/security.txt.

4.4

A vulnerability in software or in a service of a third party that many use can also be reported to the Estonian Information System Authority (Riigi Infosüsteemi Amet), the Estonian coordinator for coordinated vulnerability disclosure, anonymously if the researcher wishes (§ 5(3)(4) and § 8¹(2) of the Cybersecurity Act).

5.What you can expect

5.1

A researcher who has sent a report receives:

  1. (a)an acknowledgement within 3 business days;
  2. (b)an assessment of the report and an honest answer, including when we disagree with it;
  3. (c)information about the remedy once it has been deployed;
  4. (d)a public acknowledgement, if the researcher wishes one.

5.2

We pay no rewards for reports about this website. This Policy is a disclosure policy and not a bug bounty program.

5.3

The personal data of a researcher is processed in accordance with the Privacy Policy, which names its recipients. We do not disclose the identity of a researcher to anyone else without the consent of the researcher, unless the law requires it.