How to report
Report the vulnerability by email: security@colitu.com. Do not post it publicly, in a support ticket or on social media.
Please include in your report:
- What is affected: the domain, the app and its version number, or the server address.
- A short description of the issue and its likely impact.
- Steps to reproduce and, if possible, a proof of concept (a screenshot, an example request and response).
- How we can reach you, and whether you want to be named in the thanks list.
If you need a more secure way to communicate, say so in your first email and we will find one together.
Scope
Vulnerabilities in the following are in scope:
- colitu.com and all its subdomains
- api.colitu.com (the API the apps use)
- Windows, Linux, Android and iOS apps
- Browser extension
- Publicly reachable services of the VPN servers (connection ports, probe endpoints and web services exposed to the internet)
Out of scope
We do not accept reports about:
- Denial of service (DoS) and load tests
- Social engineering (including phishing aimed at staff or users)
- Physical attacks
- Spam and unsolicited email
- Findings in third-party services (such as hosting, payment and email providers)
- Automated scanner output without a demonstrated impact
- Findings with no impact on their own, such as a missing rate limit
Rules
- Do not access data beyond what is needed to prove the issue; do not download, modify or delete data.
- Do not access other users' accounts. Use your own account for testing.
- Do not send requests at a rate that disrupts the service.
- Give us 90 days to fix the issue. Do not publish details before that time is up or before we agree.
- Do not use a vulnerability as a bargaining chip or for pressure.
Safe harbour
We treat research you carry out in good faith and within these rules as authorised. COLITU LIMITED will not take legal action against you for research that stays within these rules. Actions outside the rules are not covered by this commitment.
Response times
- Acknowledgement of your report
- 3 business days
- First assessment (severity and scope)
- 10 business days
- Fix target: critical
- 7 days
- Fix target: high
- 30 days
- Fix target: medium
- 90 days
These times are targets. If a complex issue needs more time, we will tell you why.
Reward and thanks
We do not pay a bounty at the moment. For valid reports that we fix, we will, with your permission, list your name or handle in the thanks list below.
Thanks
No entries yet.
Found a vulnerability?
For more on our privacy and security architecture, see the security whitepaper. Security whitepaper →
COLITU LIMITED · 128 City Road, London EC1V 2NX · security.txt