Skip to content

Legal information

Security and Responsible Disclosure

Security reports are welcome. Please use a careful, minimal and coordinated process that protects users, data and service availability.

Last updated: 1 August 2026

1. Reporting

Send a concise report to viktor@vvitovec.com with the subject “PQC Radar security report”. Include the affected URL, observed behavior, reproduction steps, impact and your contact details. Do not include real credentials, private keys or unnecessary personal data in ordinary email; request a secure channel if needed.

2. Safe research boundaries

  • Use only your own accounts and data, and make the minimum requests needed to demonstrate the issue.
  • Do not access, alter, retain or disclose another person's data.
  • Do not perform denial of service, automated high-volume scanning, social engineering, phishing, credential attacks, brute force or physical attacks.
  • Do not install persistence, pivot to other systems, extract secrets or exploit beyond a minimal proof.
  • Stop immediately if you encounter sensitive data and report what occurred without copying it.

3. Authorization

This page is not blanket authorization to test PQC Radar, its providers or any customer system. If a test would go beyond passive observation or ordinary use of the public website, request and receive explicit written authorization first. Third-party services are outside scope unless their owner separately authorizes testing.

4. Response process

Receipt will be acknowledged as soon as reasonably possible. Reports are triaged by impact and reproducibility, and material issues are investigated and remediated proportionately. Please allow a reasonable remediation period before any public disclosure and coordinate timing in writing.

There is currently no paid bug-bounty program. Good-faith reports that follow these boundaries will be handled respectfully, but no reward or specific response time is promised.

5. Customer assessment data

Do not send repositories, credential material, full scan datasets or customer confidential information through the website form. Engagement-specific transfer, retention and deletion arrangements are established in writing before sensitive material is exchanged.