Responsible disclosure
If you believe you have found a security vulnerability in a system operated by SysAlbania or SySecurity, we want to hear about it and we will not take legal action against you for reporting it in good faith.
How to report
Email [email protected] with enough detail to reproduce the issue: the affected URL or component, the steps you took, and what you observed. Screenshots or a short proof-of-concept help.
What we commit to
We acknowledge every report within three working days, keep you updated while we investigate, and tell you when the issue is resolved. Where you want credit, we will name you once a fix is deployed.
Safe harbour
We will not pursue or support legal action against researchers who act in good faith, stay within the boundaries below, and give us reasonable time to fix an issue before disclosing it publicly.
Please do not
Access, modify, or delete data that is not yours. Degrade service availability, including through denial-of-service or automated high-volume scanning. Use social engineering against our staff or clients. Test systems belonging to our clients: those are covered by separate contracts and this policy does not extend to them.
Out of scope
Missing security headers with no demonstrated impact, reports generated solely by an automated scanner without validation, and issues affecting only unsupported browsers are unlikely to be actioned.