15 / SECURITY

Security

Institutional page for responsible communication concerning the security of Yamanut's public website and systems.

Current state

A specialised public vulnerability disclosure channel is in preparation.

Until a specialised channel is published, security matters may be routed through institutional contact without including unnecessary sensitive data.

How to raise a concern.

Share only what is needed to identify and route the issue, without conducting unauthorised tests.

01

Identify the public area

Indicate the affected public page or function without sending access details or private data.

02

Describe the behaviour

Explain what you observed, the potential impact and, if possible, minimal non-intrusive reproduction steps.

03

Provide a contact

Use a valid reply address for any clarification, without assuming a response within a fixed period.

Explicit boundaries.

This page does not declare programmes, rewards, response times or testing authorisations that Yamanut has not formally published. This website is not authorisation to test systems, collect third-party data or exploit vulnerabilities.

01

No announced programme

This page does not announce a bug bounty or public testing programme.

02

No implied permission

No permission is granted for intrusion, exploitation, third-party access or disclosure of private information.

03

No promised timeline

No SLA, response period or unpublished formal disclosure policy is declared.

Limit exposure.

Do not include passwords, keys, tokens, third-party personal data, exploitation evidence or complete logs. Avoid further intrusive actions. A brief initial description is sufficient for routing.

Use institutional contact.

Until a specialised public channel is available, security matters may be routed through the existing institutional address.

Report by emailcontact@yamanut.com

Related information.

Consult the Privacy policy, Contact page and Accessibility commitment.