Legal
Responsible Disclosure
If you have identified a possible security issue affecting intarmour.com or Intarmour’s web properties, this page explains how to report it responsibly.
If you have identified a possible security issue affecting intarmour.com or Intarmour’s web properties, this page explains how to report it responsibly.
01
My approach
Intarmour® di Simone Nogara (“Intarmour”) attaches great importance to the security of its systems and welcomes good-faith reports concerning possible security issues or vulnerabilities affecting intarmour.com and Intarmour’s other web properties.
The cooperation of those who carry out security research helps keep protection standards high for the benefit of all users.
02
How to report
Reports may be submitted, preferably in confidence, through one of the following channels.
- Email: advisory@intarmour.com
- Certified email (PEC): info@pec.intarmour.com / simone@pec.intarmour.com
- Threema: threema.id/ASZY9TBF
03
What to include
To allow a timely and effective assessment, please include the following elements in the report.
- the steps required to reproduce the issue;
- an assessment of the potential impact of the vulnerability;
- identification of the component, page or address affected;
- the exclusion of any personal data of third parties from the content of the report.
04
Good-faith conduct
To protect users and systems, researchers are asked to observe the following principles.
- do not access, alter, copy or exfiltrate data that is not your own;
- do not degrade, disrupt or impair the operation of the services;
- do not run high-volume automated scans or denial-of-service attacks;
- do not engage in social-engineering activities against any person;
- limit activities to what is strictly necessary to demonstrate the vulnerability.
05
Scope
This policy applies solely to Intarmour’s own web properties, including intarmour.com. Third-party systems, products and services are out of scope, even where linked or referenced.
06
Coordinated disclosure
You are asked to allow Intarmour a reasonable period to analyse and remediate the reported vulnerability before proceeding with any public disclosure.
Intarmour favours a coordinated-disclosure approach, in the interest of users and of overall security.
07
Recognition
Intarmour does not operate any paid bug-bounty programme and does not offer monetary rewards for reports. Responsible reports are, in any event, appreciated and acknowledged.
08
Protection for reporters
Research activities carried out in good faith and in compliance with this policy will not be regarded by Intarmour as unauthorised and will not give rise to legal action against those who carried them out.
Should an activity conducted in good faith result in an inadvertent breach of this policy, Intarmour will take this into account when assessing the conduct as a whole.
09
Contact
Intarmour® di Simone Nogara, Via Morazzone 4, 22100 Como (CO), Italy — VAT no. IT03817020138. Reporting channels: advisory@intarmour.com; PEC info@pec.intarmour.com / simone@pec.intarmour.com; Threema threema.id/ASZY9TBF.
10
Notice
This document is informational only and does not constitute legal advice.
Questions about this document?
If you need clarification on my policies, data processing or legal documentation, I’m happy to help.