Security

Bug Bounty Policy

We welcome security researchers who help us keep our products safe. This policy explains what you may test, how to report a vulnerability, what you can expect from us in return, and the legal protection we offer for research carried out in good faith.

1. Purpose

This program enables users and security researchers to submit vulnerabilities to Witivio on products within the scope of the program (see the "Scope" section). These submissions provide a chance to win awards in amounts to be determined by Witivio in its own discretion.

Reports received through this program are handled inside Witivio's ISO/IEC 27001:2022 certified information security management system. They are recorded as security events, triaged through our technical vulnerability management process, and tracked through to closure.

Witivio may change or cancel this Program at any time and for any reason. Similarly, these conditions may change at any time and will become applicable upon publication of the new version. The version in force on the day you submit a report is the one that applies to that report. By participating in the program, you automatically agree to the applicable terms and conditions.

2. Safe harbour

Witivio considers security research carried out in accordance with this policy to be authorised, useful and conducted in good faith. Provided that you comply with this policy at all times:

  • we will not initiate or support any legal action against you in relation to your research;
  • we will not report your activity to law enforcement as a malicious attack;
  • if a third party brings an action against you for research that complied with this policy, we will make it known that your activity was authorised.

This protection covers only the systems listed as in scope below, and only the actions strictly necessary to identify and demonstrate a vulnerability. It does not extend to third-party systems, and it cannot waive the rights of our customers, our suppliers or any other third party. Nothing in this section releases you from your obligations under applicable law, in particular data protection law. If you are unsure whether a given action is permitted, ask us at dpo@witivio.com before you carry it out.

3. Scope

The scope is limited to:

  • witivio.com and all associated sub-domains
  • aidesk-pro.com and all associated sub-domains
  • teams-pro.com and all associated sub-domains

Anything not listed above is out of scope. That includes, in particular, the third-party services and platforms we rely on, systems belonging to our customers or partners, employee devices and accounts, and our physical premises. If you believe you have found a serious issue outside this scope, you may still tell us about it, but it will not qualify for a reward.

3.1 What is not allowed

  • Social engineering attacks against our customers or staff, including phishing, vishing and pretexting
  • Attack on the service availability (e.g. Denial Of Service or spam), or any test likely to degrade performance for other users
  • Data modification, deletion or destruction of any kind
  • Physical intrusion attempts against our offices, our data centres or our hardware
  • Disclosure of data and details of vulnerabilities without our consent

3.2 Handling the data you encounter

Protecting the personal data and confidential information entrusted to us is a condition of taking part, not a formality. When testing:

  • use only accounts and data that belong to you, or test accounts we have provided;
  • keep to the minimum interaction needed to demonstrate the vulnerability, and stop as soon as it is proven;
  • if you come across personal data, credentials or any confidential information, stop immediately. Do not access, copy, download, store, share or explore it further, and tell us straight away;
  • never exfiltrate data, never establish persistence, and never pivot towards other systems, accounts or tenants;
  • redact personal data from your report and from your screenshots wherever the demonstration still holds without it;
  • securely delete any Witivio data in your possession once your report is closed, and confirm the deletion if we ask you to.

Where the platform allows it, use a recognisable user agent or a distinctive marker in your test traffic, so that our teams can tell your research apart from a real attack.

3.3 What will not be rewarded

  • Vulnerabilities related to a TLS configuration weakness
  • Submission relating to non-compliance with "best practices" (e.g. missing security headers)
  • Submission relating to DNS configurations
  • Network level Denial Of Service attacks
  • Self XSS
  • Report coming from a scanner without further explanation or POC
  • Login, logout, unauthenticated or low-value CSRF
  • Man-in-the-Middle attacks
  • Non exploitable vulnerability
  • Vulnerabilities related to rate limit

3.4 Who is eligible

Witivio employees or former employees who left the company less than a year ago are not eligible for a reward. Likewise, the close entourage of employees is not eligible for a reward.

You must also be legally able to enter into this agreement and to issue a valid invoice, and you must not be located in, or acting on behalf of anyone in, a country or entity subject to applicable financial sanctions or export restrictions. If you are a minor, we will ask for the written consent of your legal guardian before paying any reward.

4. Submission and disclosure process

If you think you've found a vulnerability in the scope described above, please send it to: dpo@witivio.com

Send one vulnerability per email, write in English or in French, and use a clear subject line. The submission must contain:

  • Scope (URL affected)
  • Type of vulnerability
  • Estimated severity
  • Description of the impact
  • Steps to reproduce
  • Ways to exploit with a valid POC
  • A way to correct
Important: A partial submission will not be eligible for a reward. Give us enough detail for someone else to reproduce the issue without guesswork.

4.1 What you can expect from us

After the reception, we will study the eligibility of the vulnerability. The time may vary depending on the type of vulnerability. We will tell you the outcome of our assessment, keep you informed as the fix progresses, and let you know once the issue is resolved. In return, we ask that you stay reachable and answer our questions if we need clarification to reproduce the finding.

Severity is assessed on the demonstrated impact on the confidentiality, integrity and availability of the affected system and of the data it holds, using the CVSS scoring system as a guide. Eligibility is entirely at our discretion and will not be subject to appeal.

If a vulnerability is raised by multiple people, only the first one raised will be eligible for a reward, the others will be classified as "duplicate". Several reports that trace back to the same root cause are treated as a single vulnerability.

4.2 Coordinated disclosure

Reported vulnerabilities must not be disclosed publicly unless expressly authorized by Witivio. In case of publication without this agreement, no reward will be given and legal proceedings may be initiated.

5. Rewards

If a vulnerability is submitted in compliance with the previously defined clauses, a reward is possible. Rewards are discretionary: the amount reflects the severity of the issue, its real impact and the quality of the report, and the decision rests with Witivio alone.

Reward cap: the maximum reward payable for any accepted report is €500 (five hundred euros), all taxes included. Any applicable VAT is included within that €500 and is not added on top, so the total amount invoiced to Witivio for a single vulnerability can never exceed €500 including VAT. Where several reports share the same root cause, the cap applies once to the group.

For all payments, an invoice is required.

The invoice must be made out to Witivio, 16A Rue de Selestat, 68000 Colmar, France, and include all the requisite information as detailed below, including your name, address, IBAN, and VAT number (if applicable), as well as a short description of service.

Payments are made via bank transfer via IBAN only, it will be made only if the bank details have been transmitted.

Payment is made within 30 days after validation and provision of the invoice.

You remain solely responsible for declaring the reward to your tax authority and for meeting any tax or social security obligations that apply to you in your country of residence.

6. Contact

Every question about this policy, and every vulnerability report, goes to dpo@witivio.com. Please do not use our support channels or social media to report a security issue.