Security policy
Read the French version
This is a translation provided for information only. The French version is the authoritative text and prevails in the event of any discrepancy. This does not deprive you of the mandatory protections of the law of your country of residence.
Security is Secufor’s core business. If you believe you have found a vulnerability in one of our products (applications, website, hosted services), we would be grateful if you reported it to us responsibly.
1. How to report a vulnerability
- By e-mail to security[at]secufor.net, describing the vulnerability, the steps to reproduce it and the estimated impact.
- The
/.well-known/security.txtfile (RFC 9116) published on this site restates these contact details in a machine-readable form. - Please do not disclose the vulnerability publicly before we have issued a fix, and do not access data that is not yours beyond what is strictly necessary to demonstrate the issue.
2. Our commitments
- Acknowledgement of receipt within 72 working hours.
- Assessment, remediation and feedback to the reporter within a time frame proportionate to the severity.
- No legal action against a good-faith reporter who complies with this policy.
- Public credit to the reporter, if they wish, once a fix has been issued.
3. Security updates
Our applications include update mechanisms; the support period for each product is stated on its page. The European obligations to report actively exploited vulnerabilities (the Cyber Resilience Act) apply from 11 September 2026: the corresponding internal process is being put in place.