Last updated: 7 August 2026

Security disclosure policy

We welcome good-faith security research. This page describes how to report a vulnerability in Alusia and what you can expect from us.

The Slovak version of this document is the governing text. This English translation is provided for information only. View the Slovak version

1. How to report

Report suspected vulnerabilities as soon as possible via security@alusia.net. Include steps to reproduce, the affected URL or component, and, if applicable, a proof of concept. Please do not publish details before we have confirmed a fix.

2. Scope

In scope: alusia.net, the application under it, and Alusia-operated APIs. Out of scope: denial-of-service testing (DoS), spam or social engineering of Alusia staff or customers, physical attacks, and third-party services we do not operate (report those to the respective provider). Use only accounts and organizations you created for testing; never access, modify, or exfiltrate another customer’s data - if a flaw exposes such data, stop and report immediately.

3. What we commit to

We acknowledge reports promptly, keep you informed of remediation progress, and credit researchers who wish to be named once the issue is resolved. We do not operate a paid bounty program at this time.

4. Good-faith research

We will not pursue legal action for security research conducted in good faith within this policy: without harming users or data, without service disruption, respecting proportionality, and giving us reasonable time to remediate before any disclosure.

Questions about these documents can be sent through the contact page while the dedicated legal address is being set up. alusia.net/en/contact