Responsible disclosure
If you believe you have identified a vulnerability, send a clear description to alberto@fontnautic.com. Include the URL, reproduction steps and impact, while avoiding accessing, modifying or downloading third-party personal data.
What we ask
- Do not carry out denial-of-service attacks, social engineering or destructive actions.
- Do not retain or extend access beyond what is necessary to demonstrate the issue.
- Do not disclose the vulnerability publicly before allowing a reasonable period for it to be corrected.
- Delete any data obtained accidentally and report it.
Website measures
The installation incorporates minimisation of exposed services, protected forms, basic abuse limitation, security headers and update policies. The hosting environment should complement these measures with external backups, 2FA, WAF, monitoring and server maintenance.
Personal data breaches
An incident affecting personal data is assessed according to its risks and the obligations to document it, notify the authority and, where applicable, communicate it to the individuals affected.