Security

Responsible disclosure
policy

If you found a security vulnerability in Colitu, tell us. This page explains how to report it and what you can expect from us.

How to report

Report the vulnerability by email: security@colitu.com. Do not post it publicly, in a support ticket or on social media.

Please include in your report:

  • What is affected: the domain, the app and its version number, or the server address.
  • A short description of the issue and its likely impact.
  • Steps to reproduce and, if possible, a proof of concept (a screenshot, an example request and response).
  • How we can reach you, and whether you want to be named in the thanks list.

If you need a more secure way to communicate, say so in your first email and we will find one together.

Scope

Vulnerabilities in the following are in scope:

  • colitu.com and all its subdomains
  • api.colitu.com (the API the apps use)
  • Windows, Linux, Android and iOS apps
  • Browser extension
  • Publicly reachable services of the VPN servers (connection ports, probe endpoints and web services exposed to the internet)

Out of scope

We do not accept reports about:

  • Denial of service (DoS) and load tests
  • Social engineering (including phishing aimed at staff or users)
  • Physical attacks
  • Spam and unsolicited email
  • Findings in third-party services (such as hosting, payment and email providers)
  • Automated scanner output without a demonstrated impact
  • Findings with no impact on their own, such as a missing rate limit

Rules

  • Do not access data beyond what is needed to prove the issue; do not download, modify or delete data.
  • Do not access other users' accounts. Use your own account for testing.
  • Do not send requests at a rate that disrupts the service.
  • Give us 90 days to fix the issue. Do not publish details before that time is up or before we agree.
  • Do not use a vulnerability as a bargaining chip or for pressure.

Safe harbour

We treat research you carry out in good faith and within these rules as authorised. COLITU LIMITED will not take legal action against you for research that stays within these rules. Actions outside the rules are not covered by this commitment.

Response times

Acknowledgement of your report
3 business days
First assessment (severity and scope)
10 business days
Fix target: critical
7 days
Fix target: high
30 days
Fix target: medium
90 days

These times are targets. If a complex issue needs more time, we will tell you why.

Reward and thanks

We do not pay a bounty at the moment. For valid reports that we fix, we will, with your permission, list your name or handle in the thanks list below.

Thanks

No entries yet.

Found a vulnerability?

For more on our privacy and security architecture, see the security whitepaper. Security whitepaper →

security@colitu.com

COLITU LIMITED · 128 City Road, London EC1V 2NX · security.txt