// vulnerability disclosure

Vulnerability Disclosure Policy

We welcome reports of security issues. If you have found a vulnerability in our website or services, we want to hear about it — and we will treat your report seriously and discreetly.

How to report

Email support@itgalya.com with the subject prefix [Security]. Our security.txt record (RFC 9116) always carries the current contact details.

To help us act quickly, please include:

  • A description of the vulnerability and its potential impact
  • The exact URL or component where you found it
  • Full reproduction steps and, where possible, a screenshot or minimal proof of concept
  • Anything else that helps us reproduce it (browser, operating system, time of testing)

How a report is handled

We will confirm that your report has arrived, review the finding, and keep you updated as the review progresses until it is closed. How long review and remediation take depends on the severity and impact of the finding, so we do not quote fixed timeframes in advance.

We ask for time to remediate before a finding is disclosed publicly, and we are happy to agree on a coordinated publication date with you.

Scope

In scope: the ITgalya website and our public digital assets.

Out of scope:

  • Denial of service (DoS/DDoS) and load or stress testing
  • Social engineering, phishing, or physical attacks against staff and facilities
  • Raw automated scanner output with no demonstrated impact
  • Theoretical configuration or header findings with no proven exploitation path
  • Vulnerabilities in third-party services — please report those to the vendor directly

Safe harbor

We will not pursue legal action against researchers acting in good faith under this policy: testing only in-scope assets, avoiding any degradation of service, not accessing other people’s data and not modifying or deleting anything, stopping immediately upon encountering sensitive data and telling us about it, and not disclosing the finding before an agreed date.

If you are unsure whether a particular action is acceptable, ask us before you perform it.

Recognition

We do not currently run a paid bug bounty. Researchers who submit the first valid report of a given issue will be offered public credit if they want it.

Preferred languages: Hebrew, English.

// next step

Not sure what the right next step is?

Use the short assessment to identify the areas worth reviewing, or tell us what changed and we will start from there.

Do not send passwords, credentials, API keys, logs or sensitive incident material through the web form.