Responsible Disclosure Policy
We take security seriously. If you discover a vulnerability in our systems or services, please report it responsibly.
Report
Email your finding to admin@rtacorp.co with a clear description, reproduction steps, and impact assessment. Encrypt sensitive details using our PGP key if available.
Acknowledgement
We will acknowledge receipt within 48 hours and provide an initial assessment within 5 business days.
Remediation
We will work to remediate confirmed vulnerabilities within a reasonable timeframe depending on severity. Critical issues are prioritised.
Disclosure
We support coordinated disclosure. We ask for a minimum 90-day embargo period before public disclosure. We will credit researchers who follow this policy.
Scope
This policy applies to vulnerabilities found in rtacorp.co and any subdomains operated by Red Team Albania SHPK, including our public website and admin console. It does not apply to third-party services we use (email, bot protection, hosting) or to any client engagement environment, which is governed by that client's own agreement.
Out of scope
- Denial of service or resource-exhaustion testing against our infrastructure
- Automated vulnerability scanning at volumes that degrade site performance for others
- Social engineering, phishing, or physical attacks against our staff or offices
- Findings that require physical access to our systems or a compromised third-party account
- Vulnerabilities in software or services we use but do not control (report those to the respective vendor)
What we ask
- Do not access, modify, or delete data that does not belong to you
- Do not perform denial of service attacks
- Do not conduct social engineering against our staff
- Stop and report as soon as you confirm a vulnerability, rather than exploring further
- Give us reasonable time to remediate before public disclosure
Safe harbor
We will not pursue legal action against researchers who make a good-faith effort to comply with this policy, including by avoiding privacy violations, service degradation, and data destruction during their testing. If legal action is initiated by a third party against you for activity conducted in accordance with this policy, we will make it known that your actions were authorised by us.
Recognition
This is a coordinated disclosure program, not a paid bug bounty; we do not currently offer monetary rewards. With your permission, we credit researchers who report a valid, in-scope finding on this page or in our advisories once it is remediated.
Ready to report a vulnerability?
admin@rtacorp.co