2026.01.15

If you believe you’ve found a security issue in anything we operate (yetisecurity.cz or any service we host), please tell us. We will not pursue legal action against researchers acting in good faith under this policy.

In scope

Out of scope

How to report

Email: security@yetisecurity.cz, encrypted with our PGP key if the material is sensitive. Fingerprint 9D3D 3C38 4412 54EA DA20 2FA7 347B 2D36 1F8F 33EC; full key at yetisecurity.cz/pgp.txt.

Please include:

What you can expect

Safe harbor

So long as you:

…we will not initiate or support legal action against you for research carried out in good faith under this policy, including under applicable Czech and EU computer-misuse and copyright law. (Legal note: have counsel confirm the exact statutory references for your jurisdiction before launch.)

Bounty

We don’t run a paid bug-bounty program. For findings we act on, we like to say thank you properly, and we’re always glad to credit you publicly if you’d like that.