Vulnerability disclosure policy
If you have found a security issue affecting Vivat Power, we would like to hear about it.
How to report
Email info@vivatpower.com with enough detail for us to reproduce the issue: the affected host or URL, the steps you took, and what you observed. Screenshots or a short recording help.
Please report in English or Spanish.
What this policy covers
This policy applies to vivatpower.com and its subdomains.
Vivat Power is part of Vivat Group, but the group and its other companies run their own disclosure processes. Issues affecting vivatgroup.net should go to Vivat Group directly, and issues affecting Klarvant Namespace Command should go to Klarvant Ltd.
What we ask
- Give us a reasonable opportunity to investigate and fix the issue before disclosing it publicly or to any third party.
- Do not access, modify or delete data that does not belong to you.
- Do not degrade our services. No denial of service, no automated scanning that generates significant load, and no social engineering of our people or our partners.
- Stay within the law.
If you follow the above in good faith, we will not pursue or support legal action against you in relation to your research.
What you can expect
- An acknowledgement that a human has read your report, normally within five working days.
- An honest assessment of whether we consider it an issue, and why.
- Credit for the finding if you would like it, and if the report is valid.
Payment
Vivat Power does not operate a bug bounty programme and does not offer payment for vulnerability reports. We are grateful for reports regardless and will say so, but please do not submit one expecting a fee, an invoice to be honoured, or a negotiation.
Out of scope
This is a static marketing website. It has no accounts, no user data and no application logic, so the following are unlikely to receive a substantive response:
- Missing security headers with no demonstrated exploit.
- Findings produced solely by an automated scanner, with no accompanying analysis.
- Reports about email configuration where the record in question is deliberate.
- Theoretical issues with no realistic path to impact.
- Anything relating to software or services we do not operate.