We take the security of our website and systems seriously. If you believe you have found a security vulnerability, we would like to hear from you. This policy explains how to report it, what we will do, and the rules we ask you to follow.
1. Scope
This policy covers:
- the website at www.3cits.co.za and 3cits.co.za; and
- the email and DNS configuration of the 3cits.co.za domain.
It does not cover:
- systems of our clients, which you must never test on the basis of this policy;
- third-party services we use, such as GitHub, Google and Zoho. Please report vulnerabilities in those services to the provider concerned under its own disclosure programme.
2. How to report
Email info@3cits.co.za with the subject "Security report". Please include:
- a description of the vulnerability and where it is (the URL or system affected);
- the steps needed to reproduce it, with any proof-of-concept;
- the potential impact, as you understand it; and
- how we can contact you, and whether you would like to be credited.
Please write in English. Our machine-readable contact details are published in security.txt.
3. What we will do
- Acknowledge your report within 3 working days.
- Investigate, confirm whether the issue is valid, and keep you informed of our progress.
- Fix confirmed vulnerabilities as quickly as we reasonably can, taking into account their severity.
- Let you know when the issue is resolved and, if you wish, credit you publicly once it is fixed.
We do not run a paid bug bounty programme.
4. Safe harbour
If you act in good faith and follow this policy, we will:
- consider your research to be authorised access to the systems in scope, for the purposes of our own systems;
- not take legal action against you, or report you to law enforcement, in relation to your research; and
- work with you to understand and resolve the issue quickly.
If a third party takes legal action against you in connection with research that complied with this policy, we will make it known that your actions were conducted in line with this policy. This safe harbour cannot authorise access to systems that we do not own, and it does not apply if you break the law or the rules below.
5. What not to do
When researching, please do not:
- carry out denial-of-service attacks or anything that degrades the availability of the website or our email;
- use social engineering, phishing or pretexting against our people, clients or suppliers;
- attempt physical access to our premises or devices;
- access, copy, modify or delete data that is not yours, beyond the minimum needed to demonstrate the vulnerability. If you encounter personal or confidential information, stop, do not keep it, and tell us;
- run high-volume automated scans or send spam;
- test systems of our clients or of third-party providers;
- demand payment or any other benefit in exchange for disclosing or withholding a vulnerability; or
- publicly disclose the vulnerability until we have fixed it or 90 days have passed since your report, whichever is sooner, unless we agree a different timeline with you in writing.
6. Low-impact reports
We value every report, but the following are unlikely to be treated as vulnerabilities on their own unless you can show a real security impact: missing security headers or cookie flags on a static site that sets no cookies, clickjacking on pages without sensitive actions, software version disclosure, and results from automated scanners without a demonstrated exploit.
7. Contact
Security reports: info@3cits.co.za (subject "Security report"). For other matters see our Company Information page.