Security policy
Good-faith researchers who follow this policy will not face legal action from Vassbrekke AS for that research.
1Contact
Report vulnerabilities to privacy@privbeacon.com. Operational questions: support@privbeacon.com. RFC 9116 file: /.well-known/security.txt.
2Response timeline
- We aim to acknowledge reports within 3 business days.
- We aim to complete an initial severity assessment within 7 days.
- Target fix windows: critical 14 days, high 30 days, medium 90 days, from the date we confirm the issue. Complex issues may take longer; we will say so.
Email a description, affected URL or component, and steps to reproduce. We prefer reports that do not include exploit payloads against production. We will not pursue legal action against good-faith researchers who follow this policy.
3Scope
Please report vulnerabilities in privbeacon.com, the public verify/badge endpoints, APIs, WordPress/Shopify plugins we publish, and the on-prem agent (https://github.com/Vassbrekke/PrivBeacon-On-Prem). Do not test other customers’ tenants, do not access data that is not yours, and do not run destructive scans.
4Dependency management
Application dependencies are pinned in package-lock.json. CI runs lint and production build. We review and apply security updates for the application, Node, PostgreSQL, and the host. There is no public bug-bounty program yet.
5Incident notification
If a personal-data breach occurs, we will notify affected customers and, where required, the relevant supervisory authority without undue delay (GDPR: without undue delay and, where feasible, within 72 hours of becoming aware). Operational incidents that only affect scan availability are surfaced as failed scans in the dashboard, not as a data-breach notice.
6Independent assessments
No independent penetration test, SOC 2, or ISO 27001 certification is published yet. Commissioning those reviews is on the operator backlog.
On-prem agent source: https://github.com/Vassbrekke/PrivBeacon-On-Prem. Privacy contact: privacy@privbeacon.com. Trust & data.
PrivBeacon fournit des analyses automatisées de confidentialité et des modèles de documents à des fins d'information uniquement. Il ne s’agit pas d’un avis juridique. Consultez un conseiller juridique qualifié avant de vous fier aux politiques générées ou aux scores de conformité pour les décisions réglementaires.