Skip to main content
Back to home

Security

Report a security vulnerability

Vigicap holds the security gaps of its users' clients. A vulnerability here is therefore never a purely internal problem, and we would rather hear about it from a researcher than from an attacker. This page sets out how to report one and what we undertake to do in return.

How to reach us

Write to the address below, in English or French. Describe the vulnerability, the steps to reproduce it and the impact you estimate. If you would like to encrypt your message, ask us for a key in a first email without technical detail.

security@vigicap.fr

This is a role address, monitored on working days. It is also published in our security.txt file, in the RFC 9116 format.

Scope

In scope

  • The vigicap.fr site and its subdomains.
  • The agency console and the client space, including their APIs.
  • The infrastructure we operate directly, and the configuration of our headers, cookies and authentication.

Out of scope

  • Our sub-processors' services (Scaleway, Brevo, Stripe), which run disclosure programmes of their own.
  • The systems of our users' clients, which we have no right to authorise you to access.
  • Automated scanner output with no demonstrated impact, and configuration findings with no exploitable consequence.

What we ask of you

These rules exist to protect third parties' data, not to obstruct you. Following them is what places you under the protection described below.

  • Do not extract, retain or disclose any data that is not yours. If you come across some, stop and tell us.
  • No denial-of-service attacks, no load testing, and no alteration or deletion of data.
  • No social engineering, phishing or attempted physical access aimed at our staff or our suppliers.
  • Use a trial account you create yourself rather than someone else's account.
  • Give us a reasonable period to fix the issue before publishing, and let us agree the date together.

Our commitments

  • If you follow the rules above, Vigicap will bring no legal proceedings and no disciplinary action against you, and will treat your research as authorised.
  • We acknowledge receipt within 2 working days.
  • We give you a first assessment — admissible or not, and our view of the severity — within 10 working days.
  • We keep you informed until the fix, then confirm the date it reached production.
  • With your agreement, we credit you by name. We do not offer a financial reward, and we prefer to write that down rather than leave it to be assumed.

security.txt

The contact details on this page are also published at the standardised location defined by RFC 9116, which most research tooling reads automatically.

See /.well-known/security.txt