Coordinated disclosure
Disclosure policy
Public processing, bounty and publication timelines — plus our 72-hour notification commitment.
72-hour commitment
Incident notification within 72 hours
If a DEFENZ vulnerability exposes hunter or company data, we notify ANTIC/MINPOSTEL and the affected people within 72 hours of becoming aware (Law 2010/012 and Law 2010/013). The notification letter is maintained by the security team and versioned in the repository.
Report processing timelines
Acknowledgement — 48 h
Your report enters triage and you get a notification. No silent waiting.
Triage — 5 business days
CVSS severity assigned, duplicates grouped, follow-ups asked explicitly and dated.
Fix verified
The company confirms the patch; you can request a retest before closure.
Bounty — 14 days
After FIX_VERIFIED, the transfer is issued within 14 days from pre-funded escrow.
Publication — 90 days maximum
Coordinated disclosure after fix and written consent; past 90 days, publication is possible with dated notice.
What we commit to
No retaliation
Good faith, respected scope, minimal proof: you are covered by the safe harbor and never pursued.
Transparency on delays
Any missed deadline is notified with a dated reason. Silence is never an answer.
Strict confidentiality
Your credentials, MSISDN and proofs stay encrypted; only your masked handle appears publicly.
Report a flaw in DEFENZ itself
Found a vulnerability in the platform? Use the secure channel below: acknowledgement within 48 h, coordinated disclosure, guaranteed confidentiality.