Responsible disclosure
Website security
Socamur welcomes responsible reports that help protect its website and the people who use it.
Architecture
The website is published as informational pages. It does not provide public administration access, account self-registration, or public file uploads. This materially reduces the exposed attack surface.
Planned controls
- Mandatory HTTPS and HSTS after all relevant hostnames are validated.
- Restrictive Content Security Policy with no third-party scripts or fonts.
- Anti-framing, MIME-sniffing and unnecessary-permission protections.
- Separation between the public website and internal operating systems.
- No credentials, secrets or private keys in the public repository.
Reporting a vulnerability
Email a technical description to operaciones@socamur.com with the subject “Website security report.” Include the affected URL, reproduction steps and observed impact. Do not include third-party data.
Expected conduct
Do not perform destructive testing, denial of service, persistent access, social engineering, data exfiltration or content alteration. Stop testing once the vulnerability is confirmed.
Scope
This policy covers only Socamur-controlled public domains that reference this policy. Third-party platforms, email, social networks, providers and customer systems are out of scope.
Last technical review: July 31, 2026.