Trust Center

Security and responsible disclosure

If you identify a vulnerability on this website or in an asset published by Grupo Bomontec, report it responsibly to contacto@bomontec.net, including evidence, scope and steps to reproduce.

How to report

What to include in the report

  • Affected asset (URL, domain, product or service) and date of discovery.
  • Description of the vulnerability and its potential impact.
  • Steps to reproduce, screenshots or non-destructive proofs of concept.
  • Scope of the testing carried out and any data accessed, where applicable.
  • Contact details for follow-up and, if you wish, for acknowledgement.

Our commitment

  • Acknowledgement of receipt and initial assessment within a reasonable time.
  • Confidential handling of the report and the evidence.
  • Coordination with the researcher on the fix and, where appropriate, publication.
  • No action will be taken against anyone who reports in good faith, within the limits described.

Limits

Avoid accessing, modifying, downloading or disclosing information beyond what is strictly necessary to demonstrate the finding. Do not run tests that degrade the service (denial of service, mass brute force), social engineering against staff or tests on third-party assets. Do not submit credentials, keys or classified information through public forms.

For clients

If you are a client of the group and detect an incident affecting a contracted service, use the support and incident channels agreed in your contract, which take priority over this public channel.