Reporting a vulnerability
Send your report to security@dapita.net. This mailbox is monitored for security matters only; for all other enquiries use info@dapita.net.
Please include, where possible: the affected product and version, a description of the issue, steps to reproduce, the potential impact, and any proof-of-concept material. Reports in English are processed fastest.
Machine-readable contact details are published at /.well-known/security.txt in accordance with RFC 9116.
What we treat as a vulnerability
A vulnerability is a weakness in a DAPITA product that can be exploited to bypass a security control. In DAPITA Core this includes, but is not limited to:
- Bypassing authentication or authorisation, including session or token forgery
- Escaping the plugin sandbox or the AppArmor confinement of a plugin
- Bypassing the plugin signature verification or the DPP message authentication
- Bypassing the SQL validator, or gaining access to another tenant's schema or data
- Disclosure of encryption keys, credentials or other secrets
- Remote code execution, privilege escalation, or unauthorised file system access
Functional defects without a security impact — incorrect calculations, layout problems, a plugin failing inside its own sandbox, or missing features — are handled as ordinary bugs through the normal update cycle and are not covered by this policy.
Our response
- Acknowledgement: within 3 business days of receipt.
- Initial assessment: within 10 business days, including whether we accept the report as a vulnerability and an indicative severity.
- Remediation: timeline depends on severity and complexity; we keep the reporter informed of progress.
- Disclosure: we coordinate public disclosure with the reporter, normally after a fix has been released.
We do not currently operate a paid bug bounty programme. We credit reporters in our release notes where they wish to be named.
Regulatory reporting
DAPITA LTD is a manufacturer of products with digital elements within the meaning of Regulation (EU) 2024/2847 (the Cyber Resilience Act). Where we become aware of an actively exploited vulnerability in a DAPITA product, or of a severe incident affecting the security of a DAPITA product, we report it to the relevant CSIRT and to ENISA within the statutory deadlines, and we notify affected customers without undue delay.
These obligations apply irrespective of the terms of any licence agreement and cannot be waived by contract.
Safe harbour
We will not pursue legal action against researchers who act in good faith under this policy. Good faith means: testing only against your own installation, making no attempt to access, modify or destroy data belonging to others, causing no degradation of service, not exfiltrating data beyond the minimum needed to demonstrate the issue, and giving us a reasonable opportunity to remediate before any public disclosure.
This policy does not authorise testing against infrastructure operated by our customers, nor against third-party services used by DAPITA products.
Customer responsibilities
DAPITA Core is self-hosted software. Each licensee is responsible for the security of the server on which it runs, including the operating system, network configuration, access control and backups.
Security updates are published through the standard update channel. Licensees are responsible for applying them. We are not liable for the consequences of a vulnerability for which a fix was made available and not installed.
Scope
This policy covers DAPITA Core and its plugins, DAPITA BaaS, DAPITA Algo, DAPITA Vault, the DAPITA App, and the websites dapita.net and core.dapita.net.
Out of scope: reports generated solely by automated scanners without a demonstrated impact, missing security headers with no exploitable consequence, social engineering of our staff or customers, denial-of-service testing, and issues in third-party services we do not control.
Contact
Security reports: security@dapita.net
General enquiries: info@dapita.net
Post: DAPITA LTD, 71-75 Shelton Street, London WC2H 9JQ, United Kingdom
Companies House: 16634395