Coordinated Vulnerability Disclosure Policy - RaiaWeb
Version 1.0 - Last updated: 2 July 2026
Courtesy translation. This English version is provided for convenience only. In the event of any discrepancy, the Portuguese version prevails.
RaiaWeb takes security seriously and welcomes the contribution of researchers and users who report vulnerabilities responsibly. This policy complies with Article 13 and Annex I, Part II, of Regulation (EU) 2024/2847 (the Cyber Resilience Act) and applies to:
- The TapNTable software and its associated licence verification and update service;
- The services and systems operated by RaiaWeb (website, Client Area, hosting infrastructure).
Manufacturer/provider: Alex Nabais Gomes (RaiaWeb) · Tax ID (NIF) 268386625 · Rua da Fonte Mestre, N.º 22, 6320-637 Soito, Portugal
1. How to report a vulnerability
Send an email to security@raiaweb.pt, in Portuguese or English, including, as far as possible:
- Description of the vulnerability and its potential impact;
- Affected product/service and version;
- Steps to reproduce (proof of concept, if available);
- Your contact details, if you wish to receive updates (anonymous reports are accepted).
2. What you can expect from us
- Acknowledgement of receipt within 3 business days;
- Triage and assessment within 10 business days, with information on the validity and severity assigned;
- Remediation without undue delay, prioritised according to severity; TapNTable security fixes are distributed free of charge through the update mechanism and, as a rule, separately from feature updates;
- Information for the reporter on progress and resolution;
- Coordinated disclosure: once a fix is available, we disclose relevant information about the corrected vulnerability (description, affected versions, mitigation) - we ask that you do not disclose publicly before the fix is released, and we propose a 90-day coordination period, adjustable by agreement;
- Public acknowledgement of your contribution, if you so wish.
3. Good faith (safe harbour)
We will not pursue any legal action against anyone who investigates and reports vulnerabilities in good faith, provided that: they do not access, alter or delete third-party data beyond what is strictly necessary to demonstrate the issue; they do not degrade the availability of the services (no DoS, spam or social engineering); they do not exploit the vulnerability beyond proof of concept; and they allow a reasonable period for remediation before any public disclosure.
4. Out of scope
- Vulnerabilities in third-party services (OVH, Innov4web, certificate authorities) - these should be reported to their respective programmes;
- Automated scanner reports without proof of exploitation;
- Configuration issues in customers' own systems (for example, TapNTable installations or VPS instances administered by the customer), where there is no vulnerability in the software itself.
5. Legal notification obligations
Without prejudice to this policy, RaiaWeb complies with the obligations to notify actively exploited vulnerabilities and severe incidents to the competent authorities (national coordinating CSIRT and ENISA), pursuant to Article 14 of Regulation (EU) 2024/2847, and the obligations to notify personal data breaches under the GDPR.
Security contact: security@raiaweb.pt · Other matters: support@raiaweb.pt