If you believe you’ve found a security issue in anything we operate (yetisecurity.cz or any service we host), please tell us. We will not pursue legal action against researchers acting in good faith under this policy.
In scope
- yetisecurity.cz and all its subdomains
- Any artifact we explicitly publish (for example our PGP key or a public report)
Out of scope
- Customer environments, even ones we’ve recently tested. Those belong to the customer; please report to them directly.
- Findings that depend on physical access, social engineering of staff, or rate-limiting/DoS.
- Reports generated by automated scanners with no manual validation.
How to report
Email: security@yetisecurity.cz, encrypted
with our PGP key if the material is sensitive. Fingerprint
9D3D 3C38 4412 54EA DA20 2FA7 347B 2D36 1F8F 33EC; full key at yetisecurity.cz/pgp.txt.
Please include:
- Steps to reproduce
- Impact (what does this let an attacker do?)
- Optional: a suggested fix or mitigation
- Your name and how you’d like to be credited (or to remain anonymous)
What you can expect
- Acknowledgement. We aim to reply within a couple of business days.
- Triage and severity assessment. Typically within a week.
- A fix or written rationale. For High and Critical findings, as quickly as we reasonably can.
- Public credit, with your consent, plus a small thank-you for findings that materially improve our security posture.
Safe harbor
So long as you:
- Make a good-faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our services
- Only interact with accounts you own or have explicit permission to access
- Report findings promptly through the channel above
…we will not initiate or support legal action against you for research carried out in good faith under this policy, including under applicable Czech and EU computer-misuse and copyright law. (Legal note: have counsel confirm the exact statutory references for your jurisdiction before launch.)
Bounty
We don’t run a paid bug-bounty program. For findings we act on, we like to say thank you properly, and we’re always glad to credit you publicly if you’d like that.