Vulnerability Disclosure Policy
Last updated: August 18, 2026
Metalcam is committed to the security of its digital products and services. This policy describes how researchers and users can report vulnerabilities and how we manage those reports.
1. Scope
This policy applies to digital assets and services operated by Metalcam and its web ecosystem.
- Web applications and services on domains managed by Metalcam.
- Integrations and proprietary components published by Metalcam.
- Systems and processes related to digital customer support.
2. Out of scope
- Third-party services outside Metalcam's operational control.
- Social engineering attacks against staff or users.
- Denial-of-service attacks (DoS / DDoS).
- Automated reports without reproducible evidence.
3. Rules for researchers
- Do not interrupt service availability.
- Do not access, modify, or delete third-party data.
- Do not publicly disclose a vulnerability before coordinating with Metalcam.
- Provide clear information to facilitate reproduction and validation.
4. Recommended report information
- Vulnerability type.
- Affected URL or asset.
- Technical description and reproduction steps.
- Estimated impact and severity.
- Available evidence (screenshots, logs, non-destructive PoC).
5. Response process
- Initial acknowledgement of the report.
- Internal technical validation.
- Prioritization according to impact and risk.
- Remediation and coordinated closure.

