Security reporting

Report a security concern.

Report suspected vulnerabilities affecting CREA-KO’s public website or publicly accessible services. Include only what is necessary to understand the issue.

Security & Standards

In scope

What to report.

This channel covers CREA-KO’s public website or publicly accessible services. It is not a route to test private, client or internal systems.

  • Suspected vulnerabilities affecting CREA-KO’s public website
  • Exposed or misconfigured publicly accessible CREA-KO services
  • Unexpected redirects from a CREA-KO public web page
  • Injected, altered or defaced public content
  • Authentication or authorization issues on a publicly accessible CREA-KO service
  • Accidental exposure of public information that should not be public
  • Impersonation of CREA-KO
  • Suspicious assets served under a CREA-KO web domain

A useful report

What to include.

  • The affected URL or public service
  • A concise description of the concern
  • Enough steps to understand and confirm it
  • The impact you observed
  • Minimal supporting evidence — only what is needed
  • Your contact details, if you would like a response

Keep it minimal

What not to send.

Send only what is needed to understand the concern. Never send more sensitive material than the report requires.

  • Passwords or private keys
  • Client or system credentials
  • Confidential institutional records
  • Unnecessary personal data
  • Executable files
  • Copied production data or databases
  • More sensitive evidence than the report requires

Where to send it

One security address.

Reports affecting CREA-KO’s public website or publicly accessible services reach the team responsible for reviewing them.

security@crea-ko.com

Include the affected public URL, a concise description of the concern and only the evidence needed to understand it.