1. Report a vulnerability
For responsible disclosure, email [email protected] with subject Security report and include the affected URL, expected and observed behavior, safe reproduction steps and an impact assessment.
2. Report abuse
For abuse, fraud, a misleading WebTrust mark, phishing or unlawful content, email [email protected] with subject Report abuse. Include the exact URL, date, context and available evidence without third-party sensitive data.
3. Good-faith research
Do not extract personal data, alter or delete information, disrupt service, use social engineering or publish details before a reasonable remediation period.
4. Coordinated disclosure
We acknowledge receipt, assess validity and coordinate remediation according to risk. Timing depends on complexity and impact. Public disclosure is coordinated after remediation or an agreed period.
5. Scope and emergencies
Scope includes webtrust.bg and its public services. For an immediate risk to people, funds or active criminal activity, also contact the competent authorities. Never send passwords, private keys or full payment credentials.
Last revised: 8 August 2026. For questions, inaccuracies or official confirmation, use the Contact page.
Official contacts →