Vulnerability Disclosure Policy
DigiT Portal is run by Digital Trust Alliance. If you believe you have found a security vulnerability in it, we want to hear from you. This page explains how to report it and what you can expect from us.
How to report
Email info@digitaltrust.lk. Please include:
- the page, address or app screen affected;
- what the vulnerability is and what an attacker could do with it;
- the steps to reproduce it, with any request, screenshot or proof of concept;
- how you would like to be credited, if at all.
Please do not report vulnerabilities through public channels such as social media, the community forum or a public issue tracker.
In scope
- this website and its application programming interfaces, on this domain;
- the mobile apps published for it.
Out of scope
- denial-of-service testing, load testing, or anything that degrades the service for others;
- social engineering, phishing, or physical attacks against people or premises;
- services run by third parties, such as payment gateways and sign-in providers - report those to the provider;
- reports from automated scanners with no demonstrated impact.
Rules for good-faith research
- Use only accounts you own or have permission to use. Access no more data than you need to show the problem, and stop as soon as you reach someone else's personal data.
- Do not change or delete data, and do not leave anything running on our systems.
- Keep what you find confidential until we have had a fair chance to fix it.
- Act within the law.
If you follow these rules, we will treat your research as authorised, work with you to understand and fix the problem, and will not pursue or support legal action against you for it.
After you report
A person reads every report. We will confirm we have received it, tell you whether we can reproduce the problem, and keep you informed while we fix it. We will agree a disclosure date with you once a fix is available. We do not run a paid bug bounty.
Machine-readable contact details are published at /.well-known/security.txt. This policy lives at /policies/vulnerability-disclosure.
