Vulnerability disclosure policy

If you have found a security issue affecting Vivat Group, we would like to hear about it.

How to report

Email security@vivatgroup.net with enough detail for us to reproduce the issue: the affected host or URL, the steps you took, and what you observed. Screenshots or a short recording help.

Please report in English or Spanish.

What we ask

  • Give us a reasonable opportunity to investigate and fix the issue before disclosing it publicly or to any third party.
  • Do not access, modify or delete data that does not belong to you.
  • Do not degrade our services. No denial of service, no automated scanning that generates significant load, no social engineering of our people or our customers.
  • Stay within the law.

If you follow the above in good faith, we will not pursue or support legal action against you in relation to your research.

What you can expect

  • An acknowledgement that a human has read your report, normally within five working days.
  • An honest assessment of whether we consider it an issue, and why.
  • Credit for the finding if you would like it, and if the report is valid.

Payment

Vivat Group does not operate a bug bounty programme and does not offer payment for vulnerability reports. We are grateful for reports regardless, and we will say so, but please do not submit one expecting a fee, an invoice to be honoured, or a negotiation.

Out of scope

The following are unlikely to receive a substantive response, because this is a static marketing website with no accounts, no user data and no application logic:

  • Missing security headers with no demonstrated exploit.
  • Findings produced solely by an automated scanner, with no accompanying analysis.
  • Reports about email configuration where the record in question is deliberate.
  • Theoretical issues with no realistic path to impact.
  • Anything relating to software or services we do not operate.

Klarvant Namespace Command is a separate product operated by Klarvant Ltd. Issues affecting the platform itself should be reported to Klarvant directly.

General enquiries