Skip to content

Responsible vulnerability reporting

Version 1.0 · effective from 15 August 2026 · AITY CLOUD SRL

Romanian version

This policy is published by AITY CLOUD SRL, a Romanian limited liability company with its registered office at SACEL no. 1003, Săcel Village, Săcel Commune, Maramureș County, postal code 437290, Romania, tax ID 39458128 (VAT RO39458128), Trade Register J2018000824245, EUID ROONRC.J2018000824245, subscribed and paid-up share capital RON 5,000, correspondence address Str. Heliade Între Vii no. 35, postal code 023382, Sector 2, Bucharest, Romania, telephone +40735850896 (Monday-Friday, 09:00-18:00 Romanian time), e-mail office@aity.ro. The Romanian and English versions are both official; in case of divergence, the Romanian version prevails.

Confidentially report a vulnerability that may affect aity services to security@aity.ro. Include the Service and URL, a description of the impact, the minimum reproduction steps, only strictly necessary technical material, and the contact details at which you want a response. Do not include secrets or personal data that are not necessary.

Scope

The policy covers public systems and applications operated by AITY CLOUD SRL. It does not authorize testing a Customer's systems, third-party providers, social engineering, phishing, physical attacks, denial of service, spam, persistence, destruction of data, or access to other persons' accounts and data.

Good-faith rules

  • Use only accounts and data that belong to you or for which you have express authorization.
  • Stop testing immediately if you encounter another person's data; do not copy, modify, download, or disclose it.
  • Limit testing to the minimum proof necessary and do not affect the Availability or integrity of the Services.
  • Do not exploit the vulnerability for another purpose or request payment in exchange for non-disclosure.
  • Give aity a reasonable period to remediate and coordinate public disclosure in writing.

If you comply with these rules and act in good faith to improve security, AITY CLOUD SRL will not initiate legal action against you merely for research authorized by this policy. This protection cannot authorize conduct prohibited by law and does not bind a third party.

What we do after a report

We acknowledge receipt, generally within no more than 2 business days, assign a case number, and conduct initial triage, generally within 5 business days. We periodically communicate status and a reasonable remediation timeline based on severity and complexity. We may request clarification and coordinate public recognition only with the reporter's agreement. There is no financial reward program unless separately announced in writing.

Reports and contact details are used for triage, remediation, coordination, compliance with legal obligations, and defense of rights, in accordance with the Privacy Policy. Vulnerabilities subject to reporting obligations are communicated to the competent authority within the statutory periods.

The machine-readable contact file is published at https://aity.ro/.well-known/security.txt and https://aity.tech/.well-known/security.txt.


Version history

Version Date Changes
1.0 15 August 2026 First published version.