العربية
Under attack? Get help nowActive incidents only
Talk to us

Responsible disclosure

How to tell us about a security weakness in this website.

Scope

This policy covers digifort.iq and its subdomains. Everything else is out of scope, including our product sites and any system we run or test for a client.

How to report

Write to [email protected] with “Security report” in the subject line. Our security.txt file lists the same address. Please do not report through the forms or the incident page.

What to include

  • The address or the part of the site affected
  • The steps to reproduce it
  • What an attacker could do with it
  • Any proof of concept, screenshots or requests, with personal data removed
  • How we can reach you

Safe harbour

If you act in good faith and follow this policy, we will treat your research as authorised, we will not take legal action against you for it, and we will not report it to the authorities.

What not to do

  • Do not access, change or delete data beyond the minimum needed to show the issue. If you reach personal data, stop and tell us.
  • Do not run denial-of-service, load or high-volume automated tests.
  • Do not use the incident page or its emergency options for testing; they exist for real incidents.
  • Do not send test requests through the forms in bulk.
  • Do not use social engineering, phishing or physical access against our staff or our offices.
  • Do not share the issue with anyone else until we have fixed it.
  • Do not keep any data you came across; delete it once you have reported.

What to expect

A person reads every report and replies from the address you wrote to. We may ask you for more detail while we confirm and fix the issue. We do not pay bounties or rewards for reports.