Security & Responsible Disclosure
Report vulnerabilities privately and with minimal data.
Bozza in revisione. Questo documento non è stato adottato come accordo vincolante e non costituisce consulenza legale.
Controls and limits
The application uses authenticated server flows, role checks and database row-level policies. Privileged access is restricted to server-side code. These are specific controls, not a promise of complete security, certification or incident-free operation.
Reporting
Email support@kartexchange.com with Security report in the subject. Include affected URL, reproduction steps, impact and minimal evidence. Do not access others’ data, disrupt service, perform social engineering or publicly disclose sensitive findings. Do not email credentials or bulk personal data.
Program status
No bounty or legal safe harbor is promised. A security.txt contact is provided for reporting. Incident classification, provider notification, breach deadlines and communications require the operator’s response process and counsel where appropriate.
Punti da esaminare con il consulente legale e il gestore
Approve scope, response ownership, incident playbook and any future safe-harbor language.
Storico delle versioni
2026-09-05 — Initial engineering draft for counsel review; not adopted. Versione permanente
