Responsible Vulnerability Disclosure Policy

To report a security vulnerability affecting vidgrosek.si, email security@vidgrosek.si; reports are handled by Vid Grosek, a Ljubljana-based penetration tester in Slovenia (services delivered through Telprom d.o.o.). Reports are acknowledged within 48 hours.

If you find a security vulnerability in my systems or projects, I appreciate it and want to make this process as easy as possible for you.

How to Report a Security Vulnerability

Send an email to security@vidgrosek.si with the following information:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any proof of concept (without exploitation)

What to Expect After You Report

  • Acknowledgment within 48 hours
  • Regular updates on progress
  • Credit in the fix announcement (if you want)

Responsible Disclosure Rules

  • Don't exploit vulnerabilities to access data that isn't yours
  • Don't perform attacks that could harm service availability
  • Report the vulnerability only to me, not publicly, until it's fixed

Learn more about Vid Grosek, who handles disclosure reports.