Security & Responsible Disclosure

Security and responsible disclosure

A public process for reporting abuse, vulnerability disclosure and coordinated remediation.

[email protected] Safe reporting Coordinated disclosure
01

1. Report a vulnerability

For responsible disclosure, email [email protected] with subject Security report and include the affected URL, expected and observed behavior, safe reproduction steps and an impact assessment.

02

2. Report abuse

For abuse, fraud, a misleading WebTrust mark, phishing or unlawful content, email [email protected] with subject Report abuse. Include the exact URL, date, context and available evidence without third-party sensitive data.

03

3. Good-faith research

Do not extract personal data, alter or delete information, disrupt service, use social engineering or publish details before a reasonable remediation period.

04

4. Coordinated disclosure

We acknowledge receipt, assess validity and coordinate remediation according to risk. Timing depends on complexity and impact. Public disclosure is coordinated after remediation or an agreed period.

05

5. Scope and emergencies

Scope includes webtrust.bg and its public services. For an immediate risk to people, funds or active criminal activity, also contact the competent authorities. Never send passwords, private keys or full payment credentials.

Currency and contact

Last revised: 8 August 2026. For questions, inaccuracies or official confirmation, use the Contact page.

Official contacts →