Security · Responsible disclosure

Report a security vulnerability

If you have found a weakness in Invoice Navigator, tell us. This page says what is in scope, what to send and what happens next.

In scope
  • invoicenavigator.eu and all subdomains
  • API endpoints (api.invoicenavigator.eu)
  • Sign-in and session handling
  • Data handling and storage
  • Invoice checking, fixing and conversion
Out of scope
  • Denial-of-service attacks
  • Social engineering or phishing
  • Physical attacks on infrastructure
  • Third-party services we use (report to them directly)
  • Findings that need unlikely user interaction
How to report

Send your findings to security@invoicenavigator.eu. Please include:

  1. 01A description of the vulnerability
  2. 02Steps to reproduce it
  3. 03Your assessment of the impact
  4. 04Proof-of-concept code, if any
  5. 05How we can reach you
What to expect
24 hWe acknowledge receipt of your report.
72 hWe confirm the vulnerability and assess its severity.
90 daysWe ask for 90 days to fix before public disclosure.
Safe harbour

We will not pursue legal action against security researchers who:

  • Act in good faith: no privacy violations, no data destruction, no service disruption
  • Only interact with accounts you own or have explicit permission to test
  • Report promptly and do not disclose publicly before the fix is out
  • Do not exploit the finding beyond what is needed to demonstrate it
Recognition

There is no bug-bounty programme. With your permission we acknowledge your contribution publicly, provide a letter of acknowledgement, and keep you informed about the fix.

TrustSecurityPrivacy policy