loading experience
Security

Found a vulnerability?

Report it responsibly: we listen, verify and fix it. Security begins with code, and with the people who help us improve it.

How to report

  • Write to us from the Contacts form choosing “Other”, or to the address listed in security.txt.
  • Describe where the problem is, how to reproduce it and the impact you observed.
  • Do not include third-party personal data: a minimal proof is enough.

Good-faith rules

  • No denial-of-service, social engineering or access to other users' data.
  • Stop as soon as you confirm the vulnerability and do not disclose it before it is fixed.
  • If you follow these rules we take no legal action for research conducted in good faith.
Our measures

NIS2-inspired measures

Risk analysis

We assess the risks of systems and suppliers and review them over time.

Incident handling

An incident register with notification deadlines (early warning, notification, final report) and, for personal data, notification to the data protection authority.

Access control

Roles and permissions, least privilege, two-step verification for administrators, lockout after repeated attempts.

Encryption

HTTPS with HSTS, BCrypt-hashed passwords, expiring tokens, sensitive data encrypted where applicable.

Logging and audit

A log of administrative actions and security events, with automatic rotation.

Application defenses

Application WAF, blocking and auto-ban of hostile IPs, rate limits, anti-bot and an in-house human check.

Continuity and backup

Scheduled database backups, with restore tested by the team.

Supply chain

Libraries and fonts hosted by us, no external CDNs for static assets, minimal and updated dependencies.