Responsible disclosure

Website security

Socamur welcomes responsible reports that help protect its website and the people who use it.

Architecture

The website is published as informational pages. It does not provide public administration access, account self-registration, or public file uploads. This materially reduces the exposed attack surface.

Planned controls

  • Mandatory HTTPS and HSTS after all relevant hostnames are validated.
  • Restrictive Content Security Policy with no third-party scripts or fonts.
  • Anti-framing, MIME-sniffing and unnecessary-permission protections.
  • Separation between the public website and internal operating systems.
  • No credentials, secrets or private keys in the public repository.

Reporting a vulnerability

Email a technical description to operaciones@socamur.com with the subject “Website security report.” Include the affected URL, reproduction steps and observed impact. Do not include third-party data.

Expected conduct

Do not perform destructive testing, denial of service, persistent access, social engineering, data exfiltration or content alteration. Stop testing once the vulnerability is confirmed.

Scope

This policy covers only Socamur-controlled public domains that reference this policy. Third-party platforms, email, social networks, providers and customer systems are out of scope.

Last technical review: July 31, 2026.