Responsible disclosure

We take the security of Travas and the data it holds seriously. If you have found a security vulnerability, we appreciate your help in disclosing it to us responsibly.

How to report

Email security@travas.eu with a description of the issue. Reports in English or Dutch are welcome. Please include:

Encrypting your report

If your report is sensitive, you can encrypt it with our OpenPGP public key: security-pubkey.asc. Verify that the key you downloaded has this fingerprint before using it:

2540 2A80 864A 46D6 3B99 1408 2BB9 C2B8 7F81 F6B2

What to expect from us

We do not currently run a paid bug-bounty programme, but we are grateful for every report and will always acknowledge good-faith research.

Please do

Please do not

Safe harbour

If you make a good-faith effort to comply with this policy during your research, we will consider your actions authorised, we will not pursue or support legal action against you, and we will work with you to understand and resolve the issue quickly.

Machine-readable version: /.well-known/security.txt