Vulnerability Disclosure

How to report a security flaw to us safely, and what we commit to in return.

In force Last updated:

The French version of this document is the official and legally binding version. This English translation is provided for convenience only.

The KATABUMP Association welcomes reports of security flaws affecting its services. This policy sets out what you may test, how to reach us, and what we undertake to do in return. It is published in accordance with RFC 9116; the corresponding file is available at /.well-known/security.txt.

1. Scope

This policy covers the systems operated by the Association:

  • katabump.com and its subdomains, including dashboard.katabump.com and control.katabump.com;
  • katabump.eu, katabump.fr and their subdomains, including this site;
  • the kdns.fr domain name service and the associated reporting form;
  • the AI assistant built into the dashboard.

Out of scope. Applications hosted by our users on their own servers, kdns.fr domain names registered by third parties, and the infrastructure of our providers (Cloudflare, OVHcloud, Clever Cloud, o2switch, Hetzner) fall outside this policy. An issue affecting one of our providers must be reported to them directly; illegal content hosted by a third party falls under the Reporting and complaints (DSA) document.

2. Testing rules

Your research must remain proportionate and cause no harm. You undertake to:

  • limit yourself to accounts and servers you control;
  • stop as soon as a flaw is demonstrated, without pushing to establish its maximum reach;
  • not access, copy, modify or delete any data belonging to a third party, and destroy any data obtained accidentally after reporting it to us;
  • not disclose any detail publicly before the flaw is fixed and we have agreed on the timing together;
  • not degrade the service.
Prohibited techniques

Excluded from this policy, and constituting a breach of Article 6 of the terms and conditions of use: denial-of-service attacks, load testing, social engineering targeting our members, our users or our providers, phishing, physical attacks, unsolicited e-mail, and brute-force attacks against accounts that are not your own.

3. How to report a flaw

Send your report to security.277hn@alias.katabump.eu. Please include:

  • the component or URL concerned;
  • the type of vulnerability and its potential impact;
  • the steps to reproduce it, as precisely as possible;
  • anything else that helps: requests, screenshots, proof-of-concept code;
  • how you would like to be credited, if you wish to be.

French and English are both accepted.

4. What you can expect from us

Step Target time
Acknowledgement of your report 3 business days
Initial assessment and severity triage 10 business days
Progress update, then at regular intervals 30 days
Coordinated disclosure, once the fix is deployed by mutual agreement, at the latest 90 days after the report

We keep you informed of the fix and credit you publicly if you wish. These are the times we aim for; the Association is run by volunteers, and a critical flaw is always handled ahead of the rest.

No bug bounty

The Association does not pay financial rewards for vulnerability reports. A report made in good faith gives rise to no entitlement to payment.

5. Our commitment to you

If you comply with this policy, we undertake to:

  • not bring civil proceedings or file a criminal complaint on account of your research;
  • not suspend your account on that ground;
  • treat your work as authorised within the meaning of Articles 323-1 et seq. of the French Criminal Code, and support you should a third party take a different view in good faith.

This commitment covers neither activity outside the scope defined in section 1, nor the techniques excluded in section 2, nor deliberate interference with third-party data. It does not bind our hosting providers, which apply their own policies.

You may also report a vulnerability to ANSSI, the French national cybersecurity agency, under Article L. 2321-4 of the French Defence Code, which protects a person who makes such a report in good faith.

6. Personal data breaches

Where the reported flaw involves personal data, we follow the notification procedure described in Article 7 of the privacy policy and Article 8 of the data processing agreement: notification to the CNIL within 72 hours where Article 33 of the GDPR requires it, and information of the data subjects where Article 34 requires it.

7. Contact

Vulnerability reports: security.277hn@alias.katabump.eu.
Legal questions: legal@katabump.com.
RFC 9116 file: /.well-known/security.txt

Esc
Type to search…