Vulnerability Disclosure Policy

Introduction

At the DeployAI Project Website, the security of our Communication and Information Systems is a top priority, in line with Commission Decision EC 2017/46.

However, vulnerabilities can never be completely eliminated, despite best efforts. When vulnerabilities are identified and exploited, it puts at risk the confidentiality, integrity or availability of the DeployAI Project Website’s systems and the information processed therein.

This vulnerability disclosure policy describes what systems and types of tests are authorised and how to send vulnerability reports. We encourage you to contact us to report potential security issues in our systems by following this policy.

Authorisation

If you are acting in good faith to identify and report vulnerabilities on DeployAI Project Website systems, while complying with this policy we will work with you to understand and resolve the issues quickly.
The DeployAI Project will not pursue legal action related to your activities of identifying vulnerabilities on our systems as long as you follow the guidelines in this policy.

Scope

This policy applies to all internet facing systems from the DeployAI Project Website, including

Any services not expressly listed above are excluded from the scope and are not authorised for testing.Moreover, vulnerabilities found in systems from vendors are also excluded from scope and should be reported directly to the vendor according to their own disclosure policy (if applicable).

Guidelines

While carrying out your activities, it is imperative that you

Do not perform the following actions

Reporting a vulnerability

What we would like to see from you

If you have identified a vulnerability, please

What you can expect from us

In return, we promise the following when you report a vulnerability to us, that is to

Get our latest news,
events and announcements!

SUBSCRIBETO OUR NEWSLETTER