πŸ‡«πŸ‡· FranΓ§ais

πŸ”’ Responsible Vulnerability Disclosure Policy

VSA encourages responsible disclosure of security vulnerabilities. We are committed to handling all security reports professionally and transparently.

πŸ“§ Security Contact

Primary Email: security@vsa.fr

Contact : https://vsa.fr/#Contacts

PGP Key: https://vsa.fr/.well-known/pgp-key.txt

Accepted Languages: French, English

πŸ“‹ Types of vulnerabilities we're looking for

πŸ”΄ Critical Priority

🟠 High Priority

🟑 Medium Priority

πŸ“ Report Format

For efficient processing, your report should include:

  1. Summary: Clear and concise description of the vulnerability
  2. Impact: Potential consequences of exploitation
  3. Reproduction Steps: Detailed step-by-step instructions
  4. Proof of Concept: Screenshots, logs, or demonstrative code
  5. Recommendations: Suggested fixes if available
  6. Environment: Browser, OS, tools used

πŸ“§ Using Encryption

Strongly recommended for critical vulnerabilities:

  1. Download our PGP key: curl https://vsa.fr/.well-known/pgp-key.txt
  2. Import the key: gpg --import vsa-pgp-key.txt
  3. Encrypt your report: gpg --armor --encrypt --recipient security@vsa.fr report.txt
  4. Send the encrypted file by email

⏱️ Processing Timeline

πŸš€ Response Times

πŸ• Target Resolution Times

πŸ† Recognition Program

We recognize security researchers' contributions in several ways:

Note: VSA does not currently offer monetary bug bounties, but we are evaluating this possibility for the future.

βš–οΈ Legal Guidelines

🀝 Researcher Protection

VSA commits not to pursue legal action against researchers who:

🚫 Prohibited Activities

πŸ“… Coordinated Disclosure

πŸ“’ Publication Policy

πŸ“ž Contact and Support

πŸ†˜ For Critical Emergencies

For critical vulnerabilities requiring immediate attention:

❓ Questions About This Policy

For any questions regarding this disclosure policy, contact us at security@vsa.fr


VSA Vulnerability Disclosure Policy

Version 1.0 - Last updated: June 27, 2025

This policy may be modified without notice. Please check this page regularly.