We find vulnerabilities in our clients' systems for a living, so we understand better than anyone the value of someone telling us about our own. If you have found a security issue in any Jaquers Ciberseguridad system, we would be grateful if you reported it by following this policy.
Scope
- jaquers.es and its subdomains.
- The DARKFORGE and TORO platforms in their public environments.
- Our email infrastructure and the services we operate directly.
Out of scope are our clients' systems and those of third-party providers (report vulnerabilities to their owner), as well as findings that require social engineering, physical access or denial of service.
How to report
- Write to hola@jaquers.es with the subject "Responsible disclosure".
- Include a description of the issue, the steps to reproduce it, the impact you estimate and, if you wish, how you would like to be credited.
- If the information is sensitive, ask us for an encrypted channel before sending the details.
What we ask of you
- Act in good faith: do not access, modify or download more data than is strictly necessary to demonstrate the issue, and do not keep it.
- Do not carry out denial of service, spam, phishing or tests on accounts that do not belong to you.
- Do not disclose the finding publicly until we have fixed it or 90 days have passed since your report, whichever comes first, unless otherwise agreed.
What we commit to doing
- Acknowledge receipt of your report within three business days.
- Keep you informed about the analysis and the fix, and let you know when it is resolved.
- Take no legal action against anyone who researches and reports in good faith, within the limits of this policy and applicable law.
- Publicly acknowledge your contribution, if you wish, once the vulnerability has been fixed. We do not currently offer monetary rewards.