Legal documents

Breakcold · Legal

Vulnerability disclosure policy

Last updated · September 3, 2026

How to report a security vulnerability in Breakcold responsibly.

This document is available in English. The English version is shown below.

On this page

1. Reporting a vulnerability

If you believe you have found a security vulnerability in a system operated by Breakcold, email support@breakcold.com with “Security vulnerability” in the subject. Logike SAS operates Breakcold. Ask us for a secure way to transfer sensitive evidence before sending it.

Include the affected URL or feature, the conditions needed to reproduce the issue, the potential impact and the minimum evidence needed to understand it. Use your own test data. Do not include passwords, usable credentials, private customer records or unnecessary personal data.

2. Scope and authorization

This policy explains how to report a suspected vulnerability. It does not grant permission to perform security testing. Before testing, obtain written authorization from Logike SAS specifying the systems, accounts, methods and limits covered. Authorization from an account holder alone does not authorize testing of Breakcold’s infrastructure.

Do not test third-party infrastructure or provider services on the basis of this policy. Stop and ask us if ownership, authorization or the safety of a test is unclear.

3. Research limits

  • Do not access, modify, export or delete another person’s data. If you unexpectedly encounter it, stop immediately and report the issue without collecting more.
  • Do not perform denial-of-service, high-volume or destructive testing, install persistent access, execute malware or disrupt the service.
  • Do not use phishing, social engineering, physical intrusion, stolen credentials or attacks against employees, customers or providers.
  • Use the least intrusive method needed to demonstrate the issue. Stop once the vulnerability is established and do not use it for personal benefit.
  • Do not demand payment or threaten disclosure, disruption or data release. Keep findings confidential while we coordinate remediation.

4. How we handle reports

We review good-faith reports, assess their impact and work to resolve confirmed vulnerabilities according to their severity. We may ask for clarification or a safe reproduction. Keep communication in the original report so evidence and updates stay together.

We aim to acknowledge reports and provide useful updates, but this policy does not promise a fixed response or remediation deadline. Do not repeat an intrusive test because a report has not yet been answered.

5. Coordinated disclosure

Contact us before publishing technical details so we can agree a reasonable disclosure schedule, considering the severity and the time needed to protect customers. Do not publish personal data, secrets or exploit instructions that expose unresolved customer risk.

We can discuss public credit if you want it. Report submission does not guarantee a bounty, payment or public acknowledgment. Any reward must be agreed separately.

6. Good-faith research

Reporting a suspected vulnerability does not itself grant testing authorization or immunity from legal action. Any specific research authorization and related commitments must be agreed in writing with Logike SAS. We cannot grant permission or waive rights on behalf of third parties or public authorities.

If you accidentally exceed written authorization or encounter another person’s data, stop, minimize harm and report what happened promptly. Do not collect further data or repeat the test while waiting for a reply.