Security and vulnerability reporting

How we protect the website and how to report a security vulnerability to us responsibly.

Last updated:

For a service that will hold your email, calendar, photos and documents, security is a basic requirement. This page describes how we protect the website and how you can responsibly report a vulnerability to us if you discover one.

1. How we protect the website

  • Encrypted traffic: the website is accessible only over HTTPS (TLS). Using the HSTS header, we instruct your browser always to open it over an encrypted connection.
  • No third-party resources: we serve fonts, images and scripts from our own server. Our Content Security Policy (Content-Security-Policy) prevents the browser from loading scripts and other resources from other addresses and from running inline scripts.
  • Security headers: the website cannot be embedded in other sites (frame-ancestors 'none'), the browser does not guess the content type (nosniff), and we send the address of the page you are coming from to other sites only in shortened form.
  • Separate sign-in: passwords and sign-ins will be handled only by the sign-in service at id.oglasna-deska.cloud, which is separate from the apps. The apps never see your password.
  • Hardened servers: the application runs in a container without administrator privileges, with a read-only file system and without unnecessary capabilities. The management interface cannot be reached from the internet.
  • Servers in the EU: the service runs on servers in the European Union.

2. Reporting a vulnerability

If you discover a vulnerability, please report it to us at info@oglasna-deska.si with the subject ‘Security’. You may write in Slovenian or English. In your message, please include:

  1. the page address or the part of the system that the vulnerability affects;
  2. a description of the vulnerability and its possible impact;
  3. the steps to reproduce it and, if possible, a proof of concept;
  4. how we can contact you if we need further information.

The contact for security reports is also published in machine-readable form in the /.well-known/security.txt file (RFC 9116).

3. How we handle reports

  • We acknowledge receipt of your report within three working days.
  • We assess the report and inform you of our assessment and the action we plan to take.
  • We fix the vulnerability within a period appropriate to its severity and let you know once it has been fixed.
  • With your consent, we credit you as the finder once the vulnerability has been fixed.

4. Rules for good-faith research

We will not treat good-faith research that follows the rules below as abuse, and we will not take legal action against you.

  • Do not access, modify or delete other people's data; if you come across such data by accident, stop and let us know.
  • Do not carry out denial-of-service attacks, large-scale automated scanning or social engineering attacks on our staff.
  • Do not test physical security or the systems of other providers.
  • Do not publish details of a vulnerability until we have fixed it or until we have agreed on disclosure.

5. Scope

These rules apply to the www.oglasna-deska.cloud website and to the id.oglasna-deska.cloud sign-in service. For Oglasna-Deska.SI, the rules published on that website apply. We do not pay monetary rewards for reported vulnerabilities.