Skip to main content

Responsible disclosure policy

No system is free of flaws, including ours. If you find one in our services, we want to know, and we want you to be able to tell us without fear. This page explains how to report a vulnerability, what we ask of you in return, and what we commit to doing.

This policy is the reference designated by the Policy: field of our security.txt file (RFC 9116).

How to report a vulnerability

Write to [email protected]. For sensitive reports, encrypt your message with our public PGP key.

An actionable report contains at least:

  • the URL, IP address or component affected;
  • a description of the vulnerability and of its potential impact;
  • reproduction steps, precise enough for us to replay the issue;
  • the date and time of your testing, which helps us correlate with our logs.

We reply in English and in French.

You can also use our Open Bug Bounty profile, a coordinated-disclosure platform. Whichever channel you choose, the rules, commitments and protections below apply, and our recognition remains non-monetary.

Scope

In scope

  • the france-nuage.fr and getbunker.net websites, and the subdomains we operate;
  • the Bunker platform: administration console and API;
  • the nuage command-line interface.

Out of scope

The following categories are not covered by this policy and must not be tested:

  • denial of service (DoS, DDoS), load testing, mass request flooding;
  • social engineering aimed at our staff, our customers or our suppliers (phishing, phone pretexting);
  • physical intrusion into our premises or datacenters, and any attempt to access the facilities;
  • third-party services we do not operate, even when our services rely on them;
  • spam, abuse of message submission forms, and bulk-sending tests;
  • reports from an automated scan with no proof of exploitability, and findings about configuration best practices with no demonstrated impact.

Data belonging to third parties is always out of scope, whatever the vector that exposes it.

What we ask of you

  • Do not take advantage of the vulnerability beyond what is needed to demonstrate it: do not extract more data than the strict minimum, and do not delete, modify or disrupt any data.
  • Do not access other people's data. If you come across it by accident, stop testing immediately and tell us in your report.
  • Do not publicly disclose the flaw before it is fixed and we have agreed on the disclosure together.
  • Stay within the scope defined above.
  • Keep no data obtained during your research: delete it as soon as the report is sent.

Our commitments

  • We acknowledge your report within 48 hours.
  • We share our assessment of the vulnerability along with an estimated fix date.
  • We keep you informed of progress until the fix ships.
  • We handle your report confidentially and pass your details to no third party without your consent.
  • We practise coordinated disclosure: once the flaw is fixed, we agree together on any publication, within 90 days of the acknowledgement. If the fix takes longer, we explain why and agree a new deadline with you.
  • We credit you by name as the finder if you wish.

Safe harbour

If you follow this policy, we treat your work as security research carried out in good faith. In that case:

  • we will take no legal action against you, civil or criminal, in connection with your report;
  • we will not ask a third party to do so on our behalf;
  • should a third party take action against you over research that complies with this policy, we will publicly confirm that your work was authorised.

This commitment covers activities carried out within the scope defined above and in line with the rules stated here. It does not cover acts performed out of scope, nor acts that deliberately harm our services, our customers or third parties. It does not override the rights of third parties whose data or systems may be affected.

Accordingly, access to our systems carried out in compliance with this policy is deemed authorised within the meaning of article 323-1 of the French Criminal Code, which penalises fraudulent access to or continued presence in an automated data processing system.

You may also report a vulnerability to the French national cybersecurity agency, ANSSI, under article L. 2321-4 of the French Defence Code, which protects good-faith reporting to the national authority.

Recognition

Bunker pays no monetary reward. We do not run a paid bug bounty programme. Our recognition takes the form of a public credit in the hall of fame below, under the name or handle of your choosing, with a link to the profile of your choosing.

If you would rather stay anonymous, just say so in your report and we will publish nothing there.

Hall of fame

We thank the researchers who have reported a vulnerability to us responsibly.

No report has been credited yet. Your name could be the first.

See also