PrivBeacon
Kom i gang
Security

Security policy

Good-faith researchers who follow this policy will not face legal action from Vassbrekke AS for that research.

On this page
  1. 01Contact
  2. 02Response timeline
  3. 03Scope
  4. 04Dependencies
  5. 05Incidents
  6. 06Independent assessments

1Contact

Report vulnerabilities to privacy@privbeacon.com. Operational questions: support@privbeacon.com. RFC 9116 file: /.well-known/security.txt.

2Response timeline

  • We aim to acknowledge reports within 3 business days.
  • We aim to complete an initial severity assessment within 7 days.
  • Target fix windows: critical 14 days, high 30 days, medium 90 days, from the date we confirm the issue. Complex issues may take longer; we will say so.

Email a description, affected URL or component, and steps to reproduce. We prefer reports that do not include exploit payloads against production. We will not pursue legal action against good-faith researchers who follow this policy.

3Scope

Please report vulnerabilities in privbeacon.com, the public verify/badge endpoints, APIs, WordPress/Shopify plugins we publish, and the on-prem agent (https://github.com/Vassbrekke/PrivBeacon-On-Prem). Do not test other customers’ tenants, do not access data that is not yours, and do not run destructive scans.

4Dependency management

Application dependencies are pinned in package-lock.json. CI runs lint and production build. We review and apply security updates for the application, Node, PostgreSQL, and the host. There is no public bug-bounty program yet.

5Incident notification

If a personal-data breach occurs, we will notify affected customers and, where required, the relevant supervisory authority without undue delay (GDPR: without undue delay and, where feasible, within 72 hours of becoming aware). Operational incidents that only affect scan availability are surfaced as failed scans in the dashboard, not as a data-breach notice.

6Independent assessments

No independent penetration test, SOC 2, or ISO 27001 certification is published yet. Commissioning those reviews is on the operator backlog.

On-prem agent source: https://github.com/Vassbrekke/PrivBeacon-On-Prem. Privacy contact: privacy@privbeacon.com. Trust & data.

PrivBeacon leverer automatiske privatlivsscanninger og dokumentskabeloner til informationsformål. Dette er ikke juridisk rådgivning. Rådfør dig med kvalificeret juridisk rådgiver, før du stoler på genererede politikker eller overholdelsesresultater for lovmæssige beslutninger.