- Home
- Responsible Disclosure
Found a vulnerability? Tell us.
We practise what we preach. If you find a security issue in our systems, we want to hear about it.
How to report
Email security@dravincon.com with a description, steps to reproduce, the affected URL and the potential impact. Our security.txt follows RFC 9116.
In scope
- www.dravincon.com and its sub-paths
Client systems are never in scope — report those directly to the client.
Please do
- Give us reasonable time to fix the issue before disclosing it publicly
- Use test data only and stop as soon as you've confirmed the issue
- Keep any personal data you encounter confidential, and delete it
Please don't
- Run denial-of-service, spam or social-engineering attacks
- Access, modify or delete data that isn't yours
- Use automated scanners that generate heavy traffic
Our promise
We'll acknowledge your report promptly, keep you updated, credit you if you wish, and won't pursue legal action for good-faith research that follows this policy.