Security policy
Good-faith researchers who follow this policy will not face legal action from Vassbrekke AS for that research.
1Contact
Report vulnerabilities to privacy@privbeacon.com. Operational questions: support@privbeacon.com. RFC 9116 file: /.well-known/security.txt.
2Response timeline
- We aim to acknowledge reports within 3 business days.
- We aim to complete an initial severity assessment within 7 days.
- Target fix windows: critical 14 days, high 30 days, medium 90 days, from the date we confirm the issue. Complex issues may take longer; we will say so.
Email a description, affected URL or component, and steps to reproduce. We prefer reports that do not include exploit payloads against production. We will not pursue legal action against good-faith researchers who follow this policy.
3Scope
Please report vulnerabilities in privbeacon.com, the public verify/badge endpoints, APIs, WordPress/Shopify plugins we publish, and the on-prem agent (https://github.com/Vassbrekke/PrivBeacon-On-Prem). Do not test other customers’ tenants, do not access data that is not yours, and do not run destructive scans.
4Dependency management
Application dependencies are pinned in package-lock.json. CI runs lint and production build. We review and apply security updates for the application, Node, PostgreSQL, and the host. There is no public bug-bounty program yet.
5Incident notification
If a personal-data breach occurs, we will notify affected customers and, where required, the relevant supervisory authority without undue delay (GDPR: without undue delay and, where feasible, within 72 hours of becoming aware). Operational incidents that only affect scan availability are surfaced as failed scans in the dashboard, not as a data-breach notice.
6Independent assessments
No independent penetration test, SOC 2, or ISO 27001 certification is published yet. Commissioning those reviews is on the operator backlog.
On-prem agent source: https://github.com/Vassbrekke/PrivBeacon-On-Prem. Privacy contact: privacy@privbeacon.com. Trust & data.
PrivBeacon leverer automatiske privatlivsscanninger og dokumentskabeloner til informationsformål. Dette er ikke juridisk rådgivning. Rådfør dig med kvalificeret juridisk rådgiver, før du stoler på genererede politikker eller overholdelsesresultater for lovmæssige beslutninger.