Vulnerability disclosure
Reporting
Send your report to security@terrarelay.eu. Include what you found, how to reproduce it and the potential impact. Please do not include customer data beyond what is needed to demonstrate the issue.
What we commit to
- We acknowledge your report.
- We will not pursue legal action against research that follows this policy in good faith.
- We keep you informed about the progress of the fix.
What we ask
- Give us reasonable time to fix the issue before you disclose it publicly.
- Do not access, change or delete data that is not yours, and do not disrupt the service.
Scope
The TerraRelay website and API. Social engineering, physical attacks and denial-of-service testing are out of scope.