DraftClauses marked Draft are awaiting review by a lawyer and may change.
Reporting a vulnerability
Reports go to contact@elastoapps.com, with “Security” in the subject line, in English, Romanian or French. A useful report contains:
- the affected URL or component
- steps to reproduce, with the relevant requests and responses
- the impact as observed, without going further than needed to show it
- an address for follow-up questions
The contact details are also published under RFC 9116 at /.well-known/security.txt.
Scope
In scope:
- www.elastoapps.com and www.elasto.ro, every page
- the contact endpoint at /api/contact
Out of scope:
- denial-of-service and load testing
- social engineering, phishing and physical attacks
- automated scanner output without a demonstrated impact
- missing headers or best-practice settings without a working exploit
Systems ELASTO built for clients belong to those clients. Reports about them are welcome here and are passed to the client, with the reporter's consent.
What happens to a reportDraft: clause awaiting legal review
- An engineer reads the report and confirms receipt by email.
- The issue is reproduced and its severity assessed.
- A fix is developed, tested and deployed.
- The reporter hears when the fix is live, and the disclosure date is agreed together.
Reporters are credited in the fix notes when they want to be. There is no paid bug bounty.
Good-faith researchDraft: clause awaiting legal review
ELASTO will not take legal action over research that follows these rules:
- access limited to the data needed to show the issue, deleted afterwards
- no disruption to the site, its visitors or its providers
- no public disclosure before the fix is live or the agreed date has passed
- a report sent promptly after the discovery
How this site is built
- Pages are generated ahead of time and served as static files over HTTPS.
- A Content Security Policy limits scripts, styles, images and connections to an allowlist of origins.
- Other sites cannot frame the pages (X-Frame-Options DENY and frame-ancestors 'none').
- No user accounts, and no third-party script before consent: Google Analytics loads only after Accept in the cookie banner.
- The contact endpoint checks the request origin, validates every field, drops submissions caught by a spam trap and limits repeated requests.
- Provider errors are logged on the server and never returned to the browser.
The providers that process data for this site are listed in the privacy policy.
Security work for other companies
This page covers ELASTO's own site. NIS2 readiness assessments, gap analysis and the technical fixes behind them are described under cybersecurity and NIS2.