We advise manufacturers on vulnerability disclosure, so we hold ourselves to the same standard. If you believe you have found a security vulnerability in cetome.com or in one of our tools (CRAscoping, CRAted, FAST, REDact, Auto VDP, dataviz), we want to hear from you.
How to report
- Email security@cetome.com , or use the contact form with “Security report” as the subject.
- Tell us which site or tool is affected, the steps to reproduce, and the impact you see. Screenshots or a proof of concept help.
- Our
security.txtis published at /.well-known/security.txt, as recommended by RFC 9116.
What you can expect
- An acknowledgement within two business days.
- An assessment and a fix or mitigation plan within thirty days for confirmed issues, sooner for critical ones.
- Credit for the report, if you wish, once the issue is resolved.
Our commitments
- We will not take legal action against researchers who act in good faith, respect this policy and the law, avoid privacy violations, data destruction and service disruption, and give us reasonable time to fix the issue before disclosing it.
- We keep your report confidential and share it only with the people needed to fix the issue.
Out of scope
- Denial-of-service testing, social engineering of our staff, and physical attacks.
- Findings that only report a missing best-practice header without a demonstrated impact.
