# 1. Vulnerability Reporting Guidelines
Send a vulnerability report to support@certifada.com with “Security report” in the subject, affected URLs, impact, and safe reproduction steps. Do not include passwords, full personal records, or destructive proof of exploitation. We review and prioritize reports; a fixed acknowledgment or resolution time is not promised by this page.
# 2. Sharing Sensitive Evidence
Contact support@certifada.com first to arrange a suitable channel for sensitive evidence. Verify the agreed channel before sending confidential information.
# 3. Ethical Research Safe Harbor
We will not initiate legal action for good-faith research that follows this policy: test only accounts and data you control, avoid disruption, do not access other people’s data, and stop and report any accidental access. Do not use social engineering, denial of service, or destructive testing. This policy does not authorize testing of third-party services or bind their operators. No reward is promised unless separately agreed.