Security & Vulnerability Disclosures
Last Updated: September 2026 • JuansTEC S.A.
1. Commitment to System Integrity
At JuansTEC S.A., security and infrastructure reliability form the foundation of our engineering discipline. We value the contribution of independent security researchers, clients, and the broader technical community in identifying and resolving potential security vulnerabilities in our systems.
This policy defines our framework for coordinated, responsible disclosure and outlines guidelines for reporting security issues discovered across our public-facing digital assets.
2. Safe Harbor Provision
If you conduct vulnerability research in good faith and in compliance with this policy:
- We consider your research to be authorized and will not initiate legal action against you.
- We will work transparently with you to understand, reproduce, and remediate the issue promptly.
- We will not request law enforcement investigations for accidental or good-faith policy violations that are reported immediately.
3. Scope & Boundaries
This policy applies exclusively to digital assets owned and managed directly by JuansTEC S.A.:
- *.juanstec.com web properties
- Primary consultation API endpoints
- Public DNS & MX configurations
- Denial of Service (DoS/DDoS)
- Phishing / Social engineering of staff
- Third-party cloud infrastructure (Azure, CDN nodes)
- Physical access to facilities
4. Research Guidelines
When investigating potential security issues, researchers must adhere to the following:
- Avoid Service Disruption: Do not degrade user experience, exhaust server resources, or disrupt ongoing production services.
- Respect Privacy: Do not view, extract, modify, or retain client data, confidential business communications, or employee credentials. If sensitive data is inadvertently encountered, cease testing and report immediately.
- No Extortion: We do not operate a commercial bug bounty program. Demands for financial compensation or threats of public release violate this safe harbor.
5. Reporting Protocol & SLAs
To submit a security vulnerability report, email our engineering security inbox with a detailed, reproducible summary:
[SECURITY DISCLOSURE] - Component NamePlease include the following details to assist in rapid verification:
- Target URL, parameter, or component affected.
- Detailed step-by-step instructions or minimal Proof of Concept (PoC) to reproduce the behavior.
- Estimated severity rating (CVSS score or impact assessment).
Response Commitment Timelines
6. Coordinated Public Disclosure
JuansTEC requests a minimum of 30 days from receipt of a verified report to develop, test, and deploy necessary remediation patches before any public disclosure is made. Coordinated disclosure ensures that fixes can be verified without placing client infrastructure or user data at premature risk.