Guidelines for the Responsible Disclosure of Security Vulnerabilities
At IT Sonix, we take the security of our website and systems seriously. However, despite our best efforts, security vulnerabilities may still exist. If you have discovered one, we would appreciate your help and a responsible report. Please contact us as soon as possible:
Email: iso@itsonix.eu
Please include the following information with your report:
- Your name and contact information
- a clear description of the security vulnerability
- The steps to reproduce the problem
- the potential impact or risk
- Relevant screenshots, log files, or code that reproduces the error (we cannot accept executable files here)
To help us focus on reports that pose an actual risk, we ask that you submit findings related to the following topics only if you can demonstrate that they lead to a specific, exploitable impact:
- Deviations from industry standards and best practices, such as missing or incomplete Content Security Policy configurations or similar configuration flaws
- Findings generated exclusively by automated scanning tools, without further analysis or supporting documentation
How We Handle Your Report
- We will confirm receipt of your report within 5 business days and keep you updated on the progress of our investigation and resolution.
- Personal data that you provide when submitting a report will be processed solely for the purpose of addressing the reported security issue. The legal basis for this processing is our legitimate interest in the security of our systems, in accordance with Article 6(1)(f) of the GDPR. Your data will be stored only as long as necessary for this purpose and will subsequently be deleted in accordance with applicable data protection regulations. You have the right at any time to request information about your stored data and to request its correction or deletion. To do so, please contact us at the address listed above.
- We will keep you informed about the status of the reported security vulnerability and notify you as soon as it has been resolved.
- We will not take legal action against you provided that you acted in good faith and complied with the requirements set forth in this policy.
- If you would like to be recognized for your contribution, we will be happy to list your name on our website as a token of our appreciation once the reported vulnerability has been successfully resolved. Please let us know in your report whether you would like to be credited, and if so, under what name.
Note: We do not currently offer monetary rewards (bug bounty program) for security reports.
Thank you very much:
We appreciate the contributions of the security community, which helps us keep our platform safe for everyone. Thank you for taking the time to act responsibly and ethically, and for helping us improve the security of our services.