Security Vulnerability Disclosure Policy

Volt Europa takes security seriously. We appreciate the efforts of security researchers who help us maintain the security of our systems and protect our users.

Contact Information

Security Team: [email protected]

PGP Key: Available here

Response Languages: English

Expected Response Time: We aim to acknowledge reports within 48 hours

Coordinated Vulnerability Disclosure

We follow the principles of coordinated vulnerability disclosure. Please follow these guidelines when reporting security vulnerabilities:

  1. Provide detailed information: Include as much detail as possible about the vulnerability to help us understand, reproduce, and properly fix the issue. This includes:
  2. Include your contact information: Please provide your contact details so we can reach you if we need additional information or want to provide updates on the fix.
  3. Maintain confidentiality: Please do not publicly disclose the vulnerability until we have addressed it and agreed on an appropriate disclosure timeline. Additionally:
  4. Publication and attribution: If you plan to publish a writeup or create educational content about the vulnerability, please contact us first to coordinate timing and review the content before publication.

Important Notice

Legal Protection: We will not pursue legal action against researchers who follow this policy and act in good faith. However, misuse or exploitation of vulnerabilities may result in legal consequences.

Out of Scope

The following issues are generally considered out of scope:

Recognition

We appreciate security researchers' contributions and may provide recognition for valid vulnerability reports, subject to the researcher's preferences and our internal policies.