Security
Report a vulnerability.
Konect Groupe welcomes reports concerning its publicly exposed systems and undertakes to handle every report in good faith.
How to report
- Reporting address
- [email protected]
- Encryption key
- Encrypted channel provided on request after identification
- Reference file
- /.well-known/security.txt
- Acknowledgement
- Within 2 business days.
- Remediation
- Qualification within 10 business days; remediation schedule communicated according to severity.
Scope
The systems publicly exposed by Konect Groupe are in scope:
- the institutional site and its public subdomains;
- public interfaces operated on its own account.
Systems belonging to clients or partners are out of scope, including where they were designed or operated by Konect Groupe. Those reports must be addressed to the organisation that owns the system.
What we ask
- Do not access, alter, extract or destroy data that is not yours.
- Do not degrade the availability of the service, and therefore refrain from any denial-of-service or bulk-sending test.
- Do not use social engineering against our staff, our clients or our suppliers.
- Keep any proof of concept to the minimum needed to demonstrate the problem.
- Allow us a reasonable period to remediate before any publication, and agree the date with us.
Our commitments
- Acknowledge every report within the stated timescale.
- Keep the person who reported informed of progress.
- Take no legal action against anyone acting in good faith and in accordance with this policy.
- Credit the contribution publicly if the person wishes, or preserve their anonymity if they prefer.
This arrangement is not a bounty programme. No payment is promised or made in respect of a report.