Vulnerability disclosure policy
Last changed on 26-09-2026
If you believe you have found a vulnerability in Vicarium, tell us. We run a service that
holds the access credentials of business owners; a report is worth more to us than silence, and
we treat it seriously.
Where to report
info@vicarium.eu, with "vulnerability" in the subject.
Encryption is welcome; ask us for a key first.
What we do
- Within three working days we confirm we received your report.
- Within ten working days we tell you whether we can reproduce it and how we assess it.
- We keep you informed until it is fixed, and tell you when it is.
- If the vulnerability turns out to be actively exploited, the reporting deadlines of article
14 of the Cyber Resilience Act apply to us: an early warning within 24 hours and an incident
notification within 72 hours to the designated authority.
- We are happy to credit you. We are equally happy to keep you anonymous.
What we ask of you
- Give us reasonable time to fix it before going public. We use 90 days as a guideline
and will talk to you if it takes longer.
- Do not change, delete or copy anyone else's data, and go no further into the systems than
needed to demonstrate the problem.
- Do not use attacks that take the service down or disturb others.
What we do not do
We pay no bounty. If you stay within the above, we will not take legal action against you.
What you need not report
Findings from an automated scan without demonstrated impact, missing security headers without
a working scenario, and issues that only occur on outdated browsers.