RESPONSIBLE DISCLOSURE
Report a vulnerability responsibly.
Contact, scope and guidelines for coordinated, good-faith disclosure.
E-project is committed to protecting the data and systems of its customers, partners and users. If you believe you have found a potential security vulnerability in our websites, applications or services, please report it responsibly so that we can verify and fix it before it can be exploited.
How to report a vulnerability
- Write to security@e-projectsrl.it, also listed in our security.txt file.
- Describe the vulnerability clearly: steps to reproduce it, the URLs or components involved, the potential impact and any supporting evidence (screenshots, logs, proof of concept), without including real personal data belonging to third parties.
- You can write to us in Italian, English or French.
Scope
- In scope: the e-projectsrl.it website and its subdomains, and the public web applications linked to E-project products.
- Out of scope: social engineering or phishing against employees and customers, physical attacks on our premises, denial-of-service attacks, spam, vulnerabilities in third-party services not operated by E-project, and issues that require physical access to a device or a man-in-the-middle attacker.
Guidelines for a responsible report
- Act in good faith and limit testing to what is strictly necessary to demonstrate the vulnerability.
- Do not access, modify, delete or exfiltrate data that does not belong to you; if you encounter personal or confidential data, stop testing immediately and let us know.
- Do not disrupt or degrade our services, for example through denial-of-service attacks or aggressive automated scanners.
- Do not publicly disclose the vulnerability before it has been fixed and without our prior consent.
If you act in line with these guidelines, E-project will not pursue legal action against you for research carried out in good faith.
Our commitment
- We acknowledge receipt of every report within a reasonable time.
- We assess the reported vulnerability and keep you updated on how it is being handled.
- We keep you informed about resolution timelines, within the limits of the confidentiality needed to protect our customers.
- We do not currently offer a paid bug bounty programme, but on request we are happy to publicly acknowledge the contribution of researchers who report vulnerabilities responsibly.