Skip to content

Vulnerability Disclosure Policy

Last updated: October 2026

1. Introduction

TunaSec z.s. is a non-profit cybersecurity organization. We take the security of our own systems seriously and welcome reports from security researchers. If you believe you have found a vulnerability in one of our systems, please let us know as described below.

2. Scope

This policy applies to tunasec.com and its subdomains operated by TunaSec, including our free online security tools. The following are out of scope:

  • Third-party services we use (e.g. hosting, email, calendar or newsletter providers). Please report those to the vendor directly.
  • Denial-of-service (DoS/DDoS) attacks and load testing.
  • Social engineering (phishing, vishing) of our members or partners, and physical attacks.
  • Output of automated scanners without a demonstrated security impact.

This policy only covers TunaSec systems. To report a vulnerability in another organization, contact that organization directly, or the national CSIRT.CZ team or NÚKIB.

3. How to Report

Email us at security@tunasec.com and include:

  • The affected URL or system
  • A description of the vulnerability and its potential impact
  • Steps to reproduce (proof of concept), screenshots or requests and responses
  • Your name or handle, if you would like to be credited

We accept reports in English, Czech and Slovak.

4. Testing Guidelines

  • Only test systems in scope, and only as far as needed to demonstrate the vulnerability.
  • Do not access, modify or delete data that does not belong to you. If you come across personal data, stop and let us know.
  • Do not degrade the availability of our services: no DoS, spam or excessive automated traffic.
  • Keep the details confidential until we have fixed the issue or 90 days have passed since your report, whichever comes first, and coordinate the disclosure with us.

5. What You Can Expect from Us

  • We will acknowledge your report within 5 business days.
  • We will keep you informed about our progress and let you know when the issue is fixed.
  • If you wish, we will publicly credit you once the issue is fixed.
  • We are a non-profit and do not run a paid bug bounty program.

6. Safe Harbor

If you act in good faith and follow this policy, we consider your research authorized and will not initiate legal action against you because of it.

7. security.txt

Our contact details are also published in machine-readable form at /.well-known/security.txt.