How we protect what we build
- Encrypted connections (HTTPS) on all our sites and security headers on the server.
- Servers with key-only access, a firewall and security updates.
- Automatic daily backups.
- Minute-by-minute monitoring with instant alerts.
- Spam-protected forms, and we only ask for the data we need.
Found a security flaw?
Thank you for helping us. Write to contact@ivseclabs.com with the subject “Security” and include: what you found, at which address or screen, steps to reproduce it and the impact you think it has. Please do not make it public until we have fixed it.
Our commitment to you
- We confirm receipt of your report within 3 business days.
- We keep you updated while we fix it.
- If you wish, we credit you publicly.
- We will not take legal action against good-faith research that follows these rules.
Research rules
- Do not access, change or delete other people’s data; use only your own accounts.
- No denial-of-service attacks or tests that affect other users.
- No social engineering, phishing or physical attacks.
- Do not send spam through our forms.
Scope
ivseclabs.com, conquian.dejatedemamadas.com and the El Conquián app. Third-party services we use (for example Hostinger or Google) are out of scope; please report those to them directly.
Rewards
We do not have a cash bounty program yet, but we are grateful for every valid report.
security.txt file
We also publish our security contact in the standard format: /.well-known/security.txt.