RaiaWeb Individual RaiaWeb Individual
  • View Cart 0
  • English English
    english English
    portuguese Português
RaiaWeb Individual
  • Domains
  • Hosting
    • Web HostingServers with WordPress, JetBuilder, JetBackup and much more, included in every plan.
    • VPS HostingVPS servers with dedicated resources, full control panel and total scalability, included in every plan.
  • Services
    • Web DevelopmentBuild your professional website with us!
  • Security & Tools
    • SSL CertificatesProtect your website and your customers' data with trusted SSL certificates, compatible with all browsers and devices.
    • -----
  • Company
    • About UsLearn about our story and what drives us.
    • Contact UsGet in touch with our team through the contact form for any questions or assistance.
  • Login
Security

Coordinated Vulnerability Disclosure Policy

  • Terms of Services
  • Privacy Policy

Coordinated Vulnerability Disclosure Policy - RaiaWeb

Version 1.0 - Last updated: 2 July 2026

Courtesy translation. This English version is provided for convenience only. In the event of any discrepancy, the Portuguese version prevails.

RaiaWeb takes security seriously and welcomes the contribution of researchers and users who report vulnerabilities responsibly. This policy complies with Article 13 and Annex I, Part II, of Regulation (EU) 2024/2847 (the Cyber Resilience Act) and applies to:

  • The TapNTable software and its associated licence verification and update service;
  • The services and systems operated by RaiaWeb (website, Client Area, hosting infrastructure).

Manufacturer/provider: Alex Nabais Gomes (RaiaWeb) · Tax ID (NIF) 268386625 · Rua da Fonte Mestre, N.º 22, 6320-637 Soito, Portugal

1. How to report a vulnerability

Send an email to security@raiaweb.pt, in Portuguese or English, including, as far as possible:

  1. Description of the vulnerability and its potential impact;
  2. Affected product/service and version;
  3. Steps to reproduce (proof of concept, if available);
  4. Your contact details, if you wish to receive updates (anonymous reports are accepted).

2. What you can expect from us

  • Acknowledgement of receipt within 3 business days;
  • Triage and assessment within 10 business days, with information on the validity and severity assigned;
  • Remediation without undue delay, prioritised according to severity; TapNTable security fixes are distributed free of charge through the update mechanism and, as a rule, separately from feature updates;
  • Information for the reporter on progress and resolution;
  • Coordinated disclosure: once a fix is available, we disclose relevant information about the corrected vulnerability (description, affected versions, mitigation) - we ask that you do not disclose publicly before the fix is released, and we propose a 90-day coordination period, adjustable by agreement;
  • Public acknowledgement of your contribution, if you so wish.

3. Good faith (safe harbour)

We will not pursue any legal action against anyone who investigates and reports vulnerabilities in good faith, provided that: they do not access, alter or delete third-party data beyond what is strictly necessary to demonstrate the issue; they do not degrade the availability of the services (no DoS, spam or social engineering); they do not exploit the vulnerability beyond proof of concept; and they allow a reasonable period for remediation before any public disclosure.

4. Out of scope

  • Vulnerabilities in third-party services (OVH, Innov4web, certificate authorities) - these should be reported to their respective programmes;
  • Automated scanner reports without proof of exploitation;
  • Configuration issues in customers' own systems (for example, TapNTable installations or VPS instances administered by the customer), where there is no vulnerability in the software itself.

5. Legal notification obligations

Without prejudice to this policy, RaiaWeb complies with the obligations to notify actively exploited vulnerabilities and severe incidents to the competent authorities (national coordinating CSIRT and ENISA), pursuant to Article 14 of Regulation (EU) 2024/2847, and the obligations to notify personal data breaches under the GDPR.

Security contact: security@raiaweb.pt · Other matters: support@raiaweb.pt

RaiaWeb Individual

RaiaWeb is a web design and hosting agency dedicated to crafting digital experiences with identity. We build modern websites, manage reliable hosting, and support our clients' online growth - with attention to detail and close, personal support.

Payments

Products

  • Web Hosting
  • VPS Hosting
  • Web Development
  • Domain Registration
  • Domain Transfer
  • SSL Certificates

Legal

  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy
  • Acceptable Use Policy
  • Data Processing Agreement
  • Domain and SSL Certificate Terms
  • Service Level Agreement
  • Report Illegal Content
  • Vulnerability Disclosure
  • Provider Switching and Transparency
  • Complaints Book

Company

  • About Us
  • Contact Us
Copyright © 2026 RaiaWeb Individual. All Rights Reserved.
  • EnglishEnglish
    english English
    portuguese Português
    No Records Found
This site uses only essential cookies required for its operation. We do not use any tracking, advertising, or third-party analytics cookies. The only data stored are your language and visual theme preferences, to provide a more comfortable browsing experience.

Generate Password
Please enter a number between 8 and 64 for the password length

Remove Sensitive Data

Are you sure you want to permanently delete this sensitive data? This action cannot be undone, and the information will no longer be accessible.