Vulnerability Disclosure Policy

ŻAK Malta welcomes responsible reports of security vulnerabilities affecting systems that we operate. This policy explains how to report an issue and the boundaries researchers must follow.

How to report a vulnerability

Email webmaster@zakmalta.org with a clear description of the issue, the affected URL or feature, steps to reproduce it, and its potential impact. Please include only the minimum evidence needed for us to understand and verify the report.

Testing boundaries

  • Do not access, copy, alter, retain, or disclose personal or confidential data.
  • Stop testing and report the issue immediately if personal data becomes accessible.
  • Do not disrupt services, degrade availability, send spam, upload malware, perform denial-of-service testing, or use social engineering.
  • Do not attempt password attacks or access another person’s account.
  • Use test accounts and non-destructive methods wherever possible.
  • Do not publicly disclose a vulnerability before ŻAK Malta has had a reasonable opportunity to investigate and remediate it.

This policy does not grant permission to access data or systems beyond what is necessary to demonstrate a vulnerability safely. Third-party services and infrastructure are outside the scope of this policy unless ŻAK Malta explicitly confirms otherwise.

What you can expect

We will review good-faith reports, work to confirm and address valid issues, and communicate with the reporter where practical. With the reporter’s permission, resolved reports may be recognised on our Security Acknowledgements page.

ŻAK Malta does not currently operate a paid bug bounty programme.