Vulnerability Disclosure · PT ↗

Security Policy

CRM-Line welcomes good-faith security research. This page describes how to report vulnerabilities responsibly and what you can expect from us in return.

Contact
security@crm-line.com · seguranca@crm-line.com (EN/PT)
PGP: not yet published — plain email accepted; treated as confidential.
RFC 9116: /.well-known/security.txt

Scope

The following assets are in scope for responsible disclosure:

Out of scope

What we commit to

What we ask of you

Safe harbour

If you conduct security research in good faith following this policy, we will:

This commitment extends to good-faith research that incidentally violates analogous EU/PT/UK cybercrime statutes (Lei do Cibercrime PT n.º 109/2009, CFAA/CMA equivalents), provided you act in accordance with this policy.

Bounties

We do not currently operate a paid bounty program. We may, at our discretion, offer rewards (acknowledgement, swag, or monetary) for impactful reports. The primary reward is recognition.

Coordinated disclosure

We are open to coordinated public disclosure of confirmed vulnerabilities once a fix has been deployed. Please coordinate timing via security@crm-line.com.