Responsible disclosure
We take the security of Travas and the data it holds seriously. If you have found a security vulnerability, we appreciate your help in disclosing it to us responsibly.
How to report
Email security@travas.eu with a description of the issue. Reports in English or Dutch are welcome. Please include:
- the type of issue and the affected URL, page or endpoint;
- steps to reproduce, and any proof-of-concept you can share;
- the potential impact, as you see it.
Encrypting your report
If your report is sensitive, you can encrypt it with our OpenPGP public key: security-pubkey.asc. Verify that the key you downloaded has this fingerprint before using it:
2540 2A80 864A 46D6 3B99 1408 2BB9 C2B8 7F81 F6B2
What to expect from us
- we acknowledge your report within 5 business days;
- we keep you informed as we investigate and work on a fix;
- we will credit you for the discovery once the issue is resolved, if you would like that.
We do not currently run a paid bug-bounty programme, but we are grateful for every report and will always acknowledge good-faith research.
Please do
- give us a reasonable amount of time to resolve the issue before disclosing it publicly;
- use test accounts and your own data where possible;
- only access the minimum amount of data needed to demonstrate the issue.
Please do not
- access, modify or delete data that is not yours, or degrade our service;
- run denial-of-service tests, automated scanners at scale, spam, or brute-force attacks;
- use social engineering, phishing, or physical attacks against our staff or infrastructure.
Safe harbour
If you make a good-faith effort to comply with this policy during your research, we will consider your actions authorised, we will not pursue or support legal action against you, and we will work with you to understand and resolve the issue quickly.
Machine-readable version: /.well-known/security.txt