Coordinated Vulnerability Disclosure Program

This document formalises what the Security page announced in principle: our program's exact scope, rules of engagement, response times, and a history of reports received.

Scope

What is covered.

The program covers all of AXIS FINANCE's and KANU's public digital assets.

  • Institutional websitewww.axis-finance.net and all its pages, in French and English.
  • Associated infrastructureDNS records, TLS certificates, security headers, publicly observable server configuration.
  • Form submission endpointServer-side processing of contact and subscription forms.
  • KANU applicationOnce published on app stores — scope will be specified at launch.

Out of scope. Denial-of-service attacks, social engineering targeting our staff, physical intrusion attempts, and any testing against third-party services we use (hosting provider, registrar) but do not directly control.

Rules of engagement

What we ask, what we guarantee.

We ask you to

Act with restraint

  • Allow us a reasonable period to remediate before any publication
  • Stop at the first sign of access to real data
  • Never degrade service availability (no large-scale automated load)
  • Never access, modify or delete a third party's data
  • Provide a reproducible report: steps, estimated impact, proof of concept where relevant
We commit to

Handle in good faith

  • Acknowledge receipt within five business days
  • Assess severity and let you know
  • Keep you informed of progress until it is fixed
  • Never pursue action against a researcher acting in good faith within this framework
  • Credit your finding in the history below, if you wish
Response times

A commitment, not a vague promise.

Target remediation time depends on severity, assessed against the CVSS 3.1 framework.

Response times by severity level
SeverityExampleAcknowledgementTarget fix
CriticalRemote code execution, access to third-party data24 hours7 days
HighAuthentication bypass, injection72 hours30 days
MediumConfiguration flaw, missing header5 business days90 days
LowDefect not affecting data security5 business daysBest effort

These are internal targets, not contractual guarantees. A complex fix may take longer; we will keep the reporting researcher informed if so.

History

Reports handled.

Published to demonstrate that this program actually works, not merely that it exists on paper.

History of security reports handled
DateSeveritySummaryStatus
No reports received to date since the program opened.

This page will be updated with each report handled, with the reporting researcher's agreement on the level of detail published.

Report a vulnerability

Write to us before writing anywhere else.

securite@axis-finance.net — acknowledgement within five business days.

Download KANU