Vulnerability Disclosure · PT ↗
Security Policy
CRM-Line welcomes good-faith security research. This page describes how to report vulnerabilities responsibly and what you can expect from us in return.
security@crm-line.com · seguranca@crm-line.com (EN/PT)
PGP: not yet published — plain email accepted; treated as confidential.
RFC 9116: /.well-known/security.txt
Scope
The following assets are in scope for responsible disclosure:
crm-line.com— institutional site (Astro static)mail.crm-line.comand email infrastructure*.crm-line.combidyou.aiandapp.bidyou.ai— SaaS product (see bidyou.ai policy)- Servers and services operated by us for clients (subject to client's prior agreement)
Out of scope
- Denial-of-service (DoS / DDoS) testing of any kind
- Social engineering of staff, customers, or suppliers
- Physical attacks against facilities or hardware
- Automated scanner output without proof-of-concept demonstrating impact
- Vulnerabilities in third-party services we rely on (please report directly: Stripe, Resend, Cloudflare, Anthropic, Webtuga, GitHub)
- Self-XSS, missing security headers without a demonstrated exploit, clickjacking on pages without sensitive actions, non-best-practice TLS configurations without a concrete attack
- Reports requiring victims to install rogue browser extensions or perform unusual actions
What we commit to
- Initial response within 48 hours (business days) acknowledging your report
- Triage within 5 business days with severity assessment
- Resolution targets: critical < 7 days · high < 30 days · medium < 90 days · low best-effort
- Updates at least every 14 days while a report is being worked on
- Credit in our acknowledgements (Hall of Fame) if you wish
What we ask of you
- Give us reasonable time to fix before public disclosure (typically 90 days, negotiable)
- Do not access, modify, or delete data that does not belong to you
- Do not deteriorate service quality for our users
- Provide a clear, reproducible proof-of-concept
- If you encounter sensitive data accidentally: stop, preserve nothing, contact us immediately
Safe harbour
If you conduct security research in good faith following this policy, we will:
- Not initiate legal action against you
- Work with you to understand and resolve the issue quickly
- Treat your findings as confidential until a fix is available
This commitment extends to good-faith research that incidentally violates analogous EU/PT/UK cybercrime statutes (Lei do Cibercrime PT n.º 109/2009, CFAA/CMA equivalents), provided you act in accordance with this policy.
Bounties
We do not currently operate a paid bounty program. We may, at our discretion, offer rewards (acknowledgement, swag, or monetary) for impactful reports. The primary reward is recognition.
Coordinated disclosure
We are open to coordinated public disclosure of confirmed vulnerabilities once a fix has been deployed. Please coordinate timing via security@crm-line.com.