Security
Security at Carica Web
Who is responsible for security at Carica Web, what our security work covers, and how to report a vulnerability to us.
Security lead
Kristiyan Lyubenov, Founder & Security Lead, Carica Web
What we do
We carry out security review, vulnerability identification and patch validation for the web applications, APIs and servers that Carica Web builds, hosts or maintains. This includes:
- authentication and admin-panel hardening;
- dependency and configuration checks;
- VPS server hardening.
Work on client systems is done only under an existing service agreement with that client.
Reporting a vulnerability
Email support@carica.website and include:
- a description of the vulnerability;
- the affected URL;
- steps to reproduce it.
We acknowledge reports within 3 business days.
When investigating, please:
- do not access or modify other users' data;
- do not run denial-of-service or social-engineering tests;
- give us reasonable time to fix the issue before any public disclosure.
We do not currently run a paid bug-bounty program.
security.txt
Our reporting contact is also published in machine-readable form at /.well-known/security.txt.