Coordinated Vulnerability Disclosure Program
This document formalises what the Security page announced in principle: our program's exact scope, rules of engagement, response times, and a history of reports received.
What is covered.
The program covers all of AXIS FINANCE's and KANU's public digital assets.
- Institutional websitewww.axis-finance.net and all its pages, in French and English.
- Associated infrastructureDNS records, TLS certificates, security headers, publicly observable server configuration.
- Form submission endpointServer-side processing of contact and subscription forms.
- KANU applicationOnce published on app stores — scope will be specified at launch.
Out of scope. Denial-of-service attacks, social engineering targeting our staff, physical intrusion attempts, and any testing against third-party services we use (hosting provider, registrar) but do not directly control.
What we ask, what we guarantee.
Act with restraint
- Allow us a reasonable period to remediate before any publication
- Stop at the first sign of access to real data
- Never degrade service availability (no large-scale automated load)
- Never access, modify or delete a third party's data
- Provide a reproducible report: steps, estimated impact, proof of concept where relevant
Handle in good faith
- Acknowledge receipt within five business days
- Assess severity and let you know
- Keep you informed of progress until it is fixed
- Never pursue action against a researcher acting in good faith within this framework
- Credit your finding in the history below, if you wish
A commitment, not a vague promise.
Target remediation time depends on severity, assessed against the CVSS 3.1 framework.
| Severity | Example | Acknowledgement | Target fix |
|---|---|---|---|
| Critical | Remote code execution, access to third-party data | 24 hours | 7 days |
| High | Authentication bypass, injection | 72 hours | 30 days |
| Medium | Configuration flaw, missing header | 5 business days | 90 days |
| Low | Defect not affecting data security | 5 business days | Best effort |
These are internal targets, not contractual guarantees. A complex fix may take longer; we will keep the reporting researcher informed if so.
Reports handled.
Published to demonstrate that this program actually works, not merely that it exists on paper.
| Date | Severity | Summary | Status |
|---|---|---|---|
| No reports received to date since the program opened. | |||
This page will be updated with each report handled, with the reporting researcher's agreement on the level of detail published.
Write to us before writing anywhere else.
securite@axis-finance.net — acknowledgement within five business days.
