responsible disclosure

Responsible
disclosure.

Found a flaw on this site? Thank you.
Here is how to report it, and what you can expect in return.

how to report

How to report

Email security@theothercompany.fr. Describe the vulnerability, the steps to reproduce it and its potential impact. A minimal proof of concept is welcome.

the rules

The rules

  • Stay within the theothercompany.fr scope and its subdomains.
  • Only access your own data, and do not modify or delete anything.
  • No denial of service, no load testing, no phishing or social engineering targeting people.
  • Give me a reasonable time to fix before any publication.

If you follow these rules, I will treat your effort in good faith, will not consider it an attack, and will not take any legal action against you.

in return

What to expect

  • An acknowledgement within a few business days.
  • An assessment, then a fix within a timeframe proportionate to severity.
  • If you wish, public thanks once the flaw is fixed.

This site does not offer a bug bounty. Reports are acknowledged, not paid.

machine-readable

security.txt

The same information is available in machine-readable form (RFC 9116): /.well-known/security.txt.