Security reporting
Report a security concern.
Report suspected vulnerabilities affecting CREA-KO’s public website or publicly accessible services. Include only what is necessary to understand the issue.
In scope
What to report.
This channel covers CREA-KO’s public website or publicly accessible services. It is not a route to test private, client or internal systems.
- Suspected vulnerabilities affecting CREA-KO’s public website
- Exposed or misconfigured publicly accessible CREA-KO services
- Unexpected redirects from a CREA-KO public web page
- Injected, altered or defaced public content
- Authentication or authorization issues on a publicly accessible CREA-KO service
- Accidental exposure of public information that should not be public
- Impersonation of CREA-KO
- Suspicious assets served under a CREA-KO web domain
A useful report
What to include.
- The affected URL or public service
- A concise description of the concern
- Enough steps to understand and confirm it
- The impact you observed
- Minimal supporting evidence — only what is needed
- Your contact details, if you would like a response
Keep it minimal
What not to send.
Send only what is needed to understand the concern. Never send more sensitive material than the report requires.
- Passwords or private keys
- Client or system credentials
- Confidential institutional records
- Unnecessary personal data
- Executable files
- Copied production data or databases
- More sensitive evidence than the report requires
Where to send it
One security address.
Reports affecting CREA-KO’s public website or publicly accessible services reach the team responsible for reviewing them.
security@crea-ko.comInclude the affected public URL, a concise description of the concern and only the evidence needed to understand it.