Security Disclosure

Security Vulnerability Disclosure Policy

At Kariha Web Agency, we take the security of our websites, software and digital services seriously. If you discover a potential security vulnerability in one of our systems, you can contact us directly so that the issue can be reviewed and handled responsibly.

How to Report a Security Vulnerability

Please send security-related reports to:

Email: security@kariha.net

To help us evaluate your report efficiently, please include as much of the following information as possible:

  • The affected website, service, application or URL
  • A short description of the security issue
  • Steps required to reproduce the issue
  • Relevant screenshots, example requests or technical details, if available
  • Contact information we may use if further details are required

Responsible Security Research

Security research should not cause harm to users, customers or systems. We therefore ask researchers to follow these principles:

  • Do not access more data than is necessary to demonstrate the issue.
  • Do not modify, delete, copy or disclose accessed data.
  • Do not perform actions that may cause service interruption or degradation.
  • Do not perform DDoS or similar denial-of-service testing.
  • Do not use social engineering, phishing or deceptive techniques against employees or users.
  • Before publicly disclosing a vulnerability, allow us reasonable time to investigate the issue and implement appropriate measures.

What Happens After a Report?

Security reports are reviewed by our technical team. If a reported issue is confirmed, it is evaluated according to its impact and priority, and appropriate technical work is planned.

We may contact the reporter if additional information is required during the investigation.

This policy does not constitute a promise of financial compensation, rewards or a bug bounty program.

Scope

This policy is primarily intended for security issues affecting websites, software and digital services managed by Kariha Web Agency.

Security issues affecting third-party software, service providers or systems not managed by Kariha should be reported directly to the relevant provider.

Privacy

Information submitted as part of a security report will only be used to evaluate, verify and resolve the reported issue.

Please do not include real customer data, passwords, access keys or other sensitive personal information unless it is strictly necessary for the report.

Contact

For security vulnerabilities and technical security reports:

security@kariha.net

902522750175