Security

Security at Carica Web

Who is responsible for security at Carica Web, what our security work covers, and how to report a vulnerability to us.

Security lead

Kristiyan Lyubenov, Founder & Security Lead, Carica Web

What we do

We carry out security review, vulnerability identification and patch validation for the web applications, APIs and servers that Carica Web builds, hosts or maintains. This includes:

  • authentication and admin-panel hardening;
  • dependency and configuration checks;
  • VPS server hardening.

Work on client systems is done only under an existing service agreement with that client.

Reporting a vulnerability

Email support@carica.website and include:

  • a description of the vulnerability;
  • the affected URL;
  • steps to reproduce it.

We acknowledge reports within 3 business days.

When investigating, please:

  • do not access or modify other users' data;
  • do not run denial-of-service or social-engineering tests;
  • give us reasonable time to fix the issue before any public disclosure.

We do not currently run a paid bug-bounty program.

security.txt

Our reporting contact is also published in machine-readable form at /.well-known/security.txt.