Responsible Disclosure Policy
How security researchers can report vulnerabilities in the Registry in good faith, what is in scope, and the commitments the Registry makes in return.
1. Reporting
Email security@eurabeltfuels.com with a description of the issue, the affected URL or endpoint, steps to reproduce, and the potential impact. Machine-readable contact details are published at /.well-known/security.txt.
2. Scope
In scope: https://ebrics.eurabeltfuels.com, including the decoder, holder services, confirmation links, the seal checker, the Legal Centre, the registry console and the /api/v1/ endpoints.
Out of scope:
- denial-of-service or volumetric testing;
- social engineering of staff, holders or counterparties;
- physical attacks;
- findings from automated scanners without a demonstrated impact;
- missing best-practice headers where no exploit is shown;
- vulnerabilities in third-party services that are not caused by the Registry's configuration.
3. Rules of engagement
- Use only accounts, codes and data you own, or test data the Registry provides.
- Do not attempt to generate, guess or enumerate real codes, ATV references or Seal IDs, and do not access, change or delete other users' data. If you encounter personal data, stop, and tell us what you saw.
- Keep automated requests to a minimum and respect rate limits.
- Give us reasonable time, normally 90 days, to fix the issue before any public disclosure.
4. Our commitments
If you act in good faith and follow this policy:
- we will acknowledge your report within 3 business days and keep you informed;
- we will not pursue legal action against you or ask law enforcement to investigate you for your research;
- with your permission, we will credit you publicly once the issue is fixed.
5. Priorities
We give the highest priority to anything that could allow a code to be forged, a verification to succeed without a valid ATV, a sealed profile or key to be exposed, a ledger entry to be changed without detection, or a console account to be taken over.