We take the security of our customer's data very seriously. If you believe you've discovered a potential security vulnerability within one of Pravica's services or products, we strongly encourage you to disclose it to us as quickly as possible and in a responsible manner. We appreciate the assistance and patience of security researchers and are committed to reviewing all reports that are disclosed to us. We will do our best to address each issue in a timely fashion, and request that you provide us with a reasonable timeframe to address the issue before public disclosure.
Please do not publicly disclose the details of any potential security vulnerabilities without express written consent from us.
To encourage responsible disclosure, we will not take legal action against security researchers in relation to the discovery and reporting of a potential security vulnerability instead, we will offer rewards to the eligible reports. This is provided that all such potential security vulnerabilities are discovered and reported strictly in accordance with this Responsible Disclosure Program. In the event of any non-compliance, we reserve all of our legal rights.
If in doubt, please contact us by sending an email to security@pravica.io
We encourage you to conduct responsible security research on our products and services. We allow you to conduct vulnerability research and testing only on our services and products to which you have authorized access.
Our apps and services are built on top of web3 technologies so there might be issues that are totally not applicable, they can be but not limited to:
You can responsibly disclose potential security vulnerabilities to the Pravica Security Team by emailing security@pravica.io Ensure that you include details of the potential security vulnerability and exploit with enough information to enable the Security Team to reproduce your steps.
When reporting a potential security vulnerability, please include as much information as possible, including:
Once you have reported a potential security vulnerability, we will contact you within 72 hours with an initial response. Going forward, we will keep you informed on our progress towards addressing the potential security vulnerability and will also notify you when the matter has been addressed and our final decision regarding the reward.
We offer rewards to the eligible issues from only recognizing the issue and thanking the researcher through our email, listing in our Hall of Fame to other reward we may decide based on the reported issues severity.
Subject to any regulatory and legal requirements, all reports will be kept strictly confidential, including the details of the potential security vulnerability as well as the identity of all researchers involved in reporting it. Once the investigation has been completed we may, subject to the researchers' consent, publicly recognize the researchers involved. If a report is found to be a duplicate or is otherwise already known to us, the report will not be eligible for any public recognition.
We ask that you maintain confidentiality and do not make your research public until we have completed our investigation and, if necessary, have remediated or mitigated the potential security vulnerability.
Please note that we may or may not compensate individuals or organizations for identifying potential or confirmed security vulnerabilities.