Found a vulnerability? We want a clear and responsible reporting path.
For vulnerabilities affecting securyza.com or a clearly identifiable Securyza service, email a technical description to info@securyza.com and identify it as a security vulnerability report in the subject. Do not include unnecessary personal data.
What the customer should get
Provide a simple path for useful security reports without encouraging destructive activity, persistent access, exfiltration or premature publication of sensitive information.
What it includes
What to send
Affected URL/asset, description, observed impact, minimal reproduction steps and non-sensitive screenshots where useful.
Avoid harm
Do not perform DoS/DDoS, social engineering, phishing, physical access, persistence, data destruction or testing of unauthorised third parties.
Data handling
If you encounter real data, stop testing, do not download more than minimally necessary and report what happened.
Scope
Public scope covers clearly identifiable Securyza assets; customer, partner and vendor systems are not automatically authorised.
Communication
Keep the report confidential while it is verified and a reasonable remediation is coordinated.
security.txt
The site also publishes /.well-known/security.txt so the reporting contact is machine-readable.
A service that is understandable, verifiable and connected to the rest of the ecosystem.
How we activate it
We start from the real environment, define scope and ownership, then implement only what can be sustained and measured.
Report
Send enough technical detail to reproduce the issue without unnecessary sensitive data.
Triage
Securyza validates the affected asset, impact and reproducibility.
Remediate
Remediation is planned according to risk, dependencies and technical availability.
Coordinate
Any public disclosure should be coordinated to avoid increasing risk to users or customers.
The right perimeter depends on risk and environment.
Connected to the other protection layers.
FAQ
Can I freely test Securyza customer systems?
No. Securyza branding does not grant permission to test customer, partner or third-party infrastructure.
Does this automatically create a bug bounty programme?
No. This policy provides a responsible disclosure channel and does not automatically promise financial rewards.
Define the perimeter before building the quote.
We can start with a Security Exposure Check, a site survey or a focused assessment and turn it into a project with clear scope, economics and ownership.