The KATABUMP Association welcomes reports of security flaws affecting its services. This policy sets out what you may test, how to reach us, and what we undertake to do in return. It is published in accordance with RFC 9116; the corresponding file is available at /.well-known/security.txt.
1. Scope
This policy covers the systems operated by the Association:
katabump.comand its subdomains, includingdashboard.katabump.comandcontrol.katabump.com;katabump.eu,katabump.frand their subdomains, including this site;- the
kdns.frdomain name service and the associated reporting form; - the AI assistant built into the dashboard.
Out of scope. Applications hosted by our users on their own servers,
kdns.fr domain names registered by third parties, and the infrastructure of our providers
(Cloudflare, OVHcloud, Clever Cloud, o2switch, Hetzner) fall outside this policy. An issue affecting
one of our providers must be reported to them directly; illegal content hosted by a third party falls
under the Reporting and complaints (DSA) document.
2. Testing rules
Your research must remain proportionate and cause no harm. You undertake to:
- limit yourself to accounts and servers you control;
- stop as soon as a flaw is demonstrated, without pushing to establish its maximum reach;
- not access, copy, modify or delete any data belonging to a third party, and destroy any data obtained accidentally after reporting it to us;
- not disclose any detail publicly before the flaw is fixed and we have agreed on the timing together;
- not degrade the service.
Excluded from this policy, and constituting a breach of Article 6 of the terms and conditions of use: denial-of-service attacks, load testing, social engineering targeting our members, our users or our providers, phishing, physical attacks, unsolicited e-mail, and brute-force attacks against accounts that are not your own.
3. How to report a flaw
Send your report to security.277hn@alias.katabump.eu. Please include:
- the component or URL concerned;
- the type of vulnerability and its potential impact;
- the steps to reproduce it, as precisely as possible;
- anything else that helps: requests, screenshots, proof-of-concept code;
- how you would like to be credited, if you wish to be.
French and English are both accepted.
4. What you can expect from us
| Step | Target time |
|---|---|
| Acknowledgement of your report | 3 business days |
| Initial assessment and severity triage | 10 business days |
| Progress update, then at regular intervals | 30 days |
| Coordinated disclosure, once the fix is deployed | by mutual agreement, at the latest 90 days after the report |
We keep you informed of the fix and credit you publicly if you wish. These are the times we aim for; the Association is run by volunteers, and a critical flaw is always handled ahead of the rest.
The Association does not pay financial rewards for vulnerability reports. A report made in good faith gives rise to no entitlement to payment.
5. Our commitment to you
If you comply with this policy, we undertake to:
- not bring civil proceedings or file a criminal complaint on account of your research;
- not suspend your account on that ground;
- treat your work as authorised within the meaning of Articles 323-1 et seq. of the French Criminal Code, and support you should a third party take a different view in good faith.
This commitment covers neither activity outside the scope defined in section 1, nor the techniques excluded in section 2, nor deliberate interference with third-party data. It does not bind our hosting providers, which apply their own policies.
You may also report a vulnerability to ANSSI, the French national cybersecurity agency, under Article L. 2321-4 of the French Defence Code, which protects a person who makes such a report in good faith.
6. Personal data breaches
Where the reported flaw involves personal data, we follow the notification procedure described in Article 7 of the privacy policy and Article 8 of the data processing agreement: notification to the CNIL within 72 hours where Article 33 of the GDPR requires it, and information of the data subjects where Article 34 requires it.
7. Contact
Vulnerability reports: security.277hn@alias.katabump.eu.
Legal questions: legal@katabump.com.
RFC 9116 file: /.well-known/security.txt