Vulnerability Disclosure Policy
- גרסה
- טרם נקבע
- עודכן לאחרונה
- טרם נקבע
- הנוסח המחייב
- English
- מקור הנוסח
- נספח A.5 במסמך האסטרטגיה
הנוסח האנגלי הוא המחייב לגבי מסמך זה.
Last updated: placeholder: date.
Our commitment
We want to hear about security problems in our products and our website. If you report one in good faith under this policy, we will not pursue legal action against you, we will acknowledge your report, and we will keep you informed until it is resolved.
Scope
In scope: placeholder: domain and its subdomains; the Regulaxy software distributed by us placeholder: supported versions.
Out of scope: third-party services we do not operate; customers' own Regulaxy installations (report those to the customer — we will help coordinate if you ask); findings from automated scanners with no demonstrated impact; missing security headers or best-practice deviations without a working exploit path; social engineering of our staff; physical attacks; denial-of-service testing.
How to report
Email security@placeholder: domain, encrypted with our PGP key at /.well-known/pgp-key.txt if the finding is sensitive.
Please include: what the issue is, where it is, how to reproduce it step by step, what an attacker could achieve, and any proof-of-concept. Hebrew or English are both fine.
What we ask of you
- Give us reasonable time to fix it before disclosing publicly — we ask for 90 days, and will tell you if we need longer and why.
- Do not access, modify or delete data that is not yours. If you encounter personal data, stop and tell us.
- Do not degrade our service or our customers'. No denial-of-service, no spam, no automated high-volume scanning.
- Test only against systems in scope, and only against your own accounts.
What we commit to
| Stage | Our target |
|---|---|
| Acknowledge receipt | placeholder: 3 business days |
| Initial assessment and severity | placeholder: 10 business days |
| Status updates | At least every placeholder: 14 days until resolved |
| Fix or documented mitigation | Target placeholder: 90 days, sooner for critical severity |
We will credit you in our advisory and on /trust/hall-of-fame if you would like to be named.
Rewards
placeholder: We do not currently operate a paid bug-bounty programme. — Say this plainly if it is true. Do not imply a reward that does not exist.
Safe harbour
Activity conducted in a manner consistent with this policy will be considered authorised. We will not initiate or support legal action against you for it, and if a third party brings action against you for such activity, we will make it known that your actions were authorised. This does not cover activity outside this policy, and it cannot waive the rights of third parties. counsel: safe-harbour wording must be lawyer-reviewed — it is a binding promise.
היסטוריית שינויים
אין עדיין רשומות. הרשומה הראשונה תיווצר עם פרסום הגרסה המאושרת, ומכאן ואילך כל שינוי מהותי יתועד כאן עם תאריך ומספר גרסה.
שאלה על המסמך הזה
אפשר לפנות אלינו בכתובת placeholder: privacy@….
# ─────────────────────────────────────────────────────────────────────────────
# ⛔ DRAFT — every [PLACEHOLDER] below must be replaced before this domain goes
# live. RFC 9116 makes `Contact` and `Expires` MANDATORY, and `Expires` must
# appear exactly once and be less than a year in the future. A security.txt
# that does not parse, or one that has expired, is worse on a security
# vendor's domain than none at all — researchers do check.
#
# ⚠ `Expires` is a MAINTENANCE COMMITMENT. Put a calendar reminder at eleven
# months. Renewing it is a two-minute job that nobody remembers to do.
#
# Source: WEBSITE-STRATEGY.md Appendix A.4. Kept in sync with the human-
# readable policy at /trust/vulnerability-disclosure, which renders this
# exact file so the two cannot drift.
# ─────────────────────────────────────────────────────────────────────────────
# Security contact information for [PLACEHOLDER: company name]
# See https://www.rfc-editor.org/rfc/rfc9116
Contact: mailto:security@[PLACEHOLDER: domain]
Contact: https://[PLACEHOLDER: domain]/trust/vulnerability-disclosure
Expires: [PLACEHOLDER: e.g. 2027-06-30T23:59:00.000Z]
Preferred-Languages: he, en
Canonical: https://[PLACEHOLDER: domain]/.well-known/security.txt
Policy: https://[PLACEHOLDER: domain]/trust/vulnerability-disclosure
Acknowledgments: https://[PLACEHOLDER: domain]/trust/hall-of-fame
Encryption: https://[PLACEHOLDER: domain]/.well-known/pgp-key.txt
Hiring: https://[PLACEHOLDER: domain]/company/careers