Diplomats.Digital
Legal

Security and Vulnerability Disclosure

Last reviewed: 3 September 2026

Introduction

Diplomats.Digital takes the security of its website and information seriously. If you become aware of a suspected security vulnerability through normal use, passive observation, or inadvertent discovery, please report it privately to security@diplomats.digital.

Reporting a Potential Vulnerability

Please provide an actionable plain-text report containing:

  • The affected URL or component
  • A concise description of the suspected vulnerability
  • Exact steps required to reproduce it
  • The demonstrated or reasonably expected security impact
  • The date and time of discovery
  • Redacted, non-executable evidence where necessary

Do not send passwords, personal data, executable files, or links requiring the download of files.

Scope

This reporting process applies only to diplomats.digital and first-party website functionality directly controlled by Diplomats.Digital.

Third-party platforms, hosting infrastructure, services, and products are outside the scope of this policy and should be reported directly to their respective operators.

No Authorization to Test

Neither this policy nor the publication of security.txt grants permission to conduct security testing.

Without prior written authorization, do not:

  • Use automated vulnerability scanners or high-volume testing
  • Attempt to bypass authentication or security controls
  • Access, copy, modify, delete, or retain data
  • Test accounts, systems, or information that you do not own
  • Disrupt or degrade the availability of any service
  • Conduct denial-of-service testing
  • Perform phishing, social engineering, or physical-security testing
  • Test infrastructure or services operated by third parties

If you encounter personal, confidential, or otherwise sensitive information, stop immediately and report what you observed without retaining the information.

No Bug Bounty or Compensation

Diplomats.Digital does not operate a bug-bounty programme and does not promise or offer financial compensation for unsolicited testing or vulnerability reports.

Submitting a report does not create any entitlement to payment, reward, contractual relationship, or public recognition. Any acknowledgment is entirely at the discretion of Diplomats.Digital.

Report Handling

We may review reports that contain sufficient technical information to identify, reproduce, and assess a potential vulnerability.

Generic pre-disclosure inquiries, automated scanner output without demonstrated security impact, requests for payment, and reports that do not contain actionable technical details may receive no response.

Where a report is substantiated, Diplomats.Digital may contact the reporter for clarification and coordinate appropriate remediation. We do not guarantee a response or remediation timeline.

Confidentiality

Potential vulnerabilities must not be publicly disclosed without prior written authorization from Diplomats.Digital.

This policy is intended to provide a reporting channel. It does not create contractual obligations, grant authorization for security testing, or waive any rights.