Skip to main content
DEFENZ

Coordinated disclosure

Disclosure policy

Public processing, bounty and publication timelines — plus our 72-hour notification commitment.

72-hour commitment

Incident notification within 72 hours

If a DEFENZ vulnerability exposes hunter or company data, we notify ANTIC/MINPOSTEL and the affected people within 72 hours of becoming aware (Law 2010/012 and Law 2010/013). The notification letter is maintained by the security team and versioned in the repository.

Report processing timelines

  1. Acknowledgement — 48 h

    Your report enters triage and you get a notification. No silent waiting.

  2. Triage — 5 business days

    CVSS severity assigned, duplicates grouped, follow-ups asked explicitly and dated.

  3. Fix verified

    The company confirms the patch; you can request a retest before closure.

  4. Bounty — 14 days

    After FIX_VERIFIED, the transfer is issued within 14 days from pre-funded escrow.

  5. Publication — 90 days maximum

    Coordinated disclosure after fix and written consent; past 90 days, publication is possible with dated notice.

What we commit to

  • No retaliation

    Good faith, respected scope, minimal proof: you are covered by the safe harbor and never pursued.

  • Transparency on delays

    Any missed deadline is notified with a dated reason. Silence is never an answer.

  • Strict confidentiality

    Your credentials, MSISDN and proofs stay encrypted; only your masked handle appears publicly.

Report a flaw in DEFENZ itself

Found a vulnerability in the platform? Use the secure channel below: acknowledgement within 48 h, coordinated disclosure, guaranteed confidentiality.