Security Policy
This page outlines our disclosure process, contacts, and service level agreements (SLA).
Disclosure Contacts
- Email: info@indrasnet.ee
- Language: English only
- Format: plain text email with clear reproduction steps, affected URL(s), and observable impact
- security.txt: /.well-known/security.txt
Scope
- indrasnet.ee static site and published documents
- public IndrasNet-controlled demonstrator interfaces intended for external access
Out of scope: third-party infrastructure outside IndrasNet OÜ control.
Service Level Agreement (SLA)
| Step | Timeline | Details |
|---|---|---|
| Acknowledgment | within 48 hours | Confirmation that the report was received |
| Assessment | as soon as reasonably possible | Initial severity and reproducibility review |
| Fix Coordination | Depends on severity | Confirmed issues are prioritized and handled accordingly |
| Publication | After containment or fix | Coordinated disclosure only |
Disclosure Process
- Send report → info@indrasnet.ee
- Acknowledgment → within 24 hours
- Assessment & classification → within 48 hours
- Fix coordination → according to SLA
- Publication → after fix release
Testing Rules
- No destructive testing
- No denial-of-service testing
- No credential attacks or social engineering
- No access, modification, copying, or exfiltration of non-public data
Bug Bounty
IndrasNet OÜ does not currently operate a public bug bounty program, and monetary rewards for vulnerability reports are not guaranteed.