Vulnerability disclosure policy
RackList treats good-faith security research as a useful contribution to the safety of its users and of the hosting providers it lists. This policy sets out the scope you are authorised to test, the techniques we forbid, the deadlines we commit to, and the protection you get when you stay within that frame. It supplements, and does not replace, the platform Terms of Service.
Document version 1.0
Read the scope before you test. A vulnerability found outside the authorised scope does not benefit from the no-prosecution commitment set out in article 8, even when reported in good faith.
Purpose
This policy sets out the terms on which anyone may look for, and then report to the publisher, a security vulnerability affecting the RackList platform. It amounts to express written authorisation to carry out the testing described in article 3, within the limits set by articles 4 and 5. It is open to everyone, with no requirement for an account, a nationality, a professional qualification, or prior membership of any programme.
Definitions
- Researcher
- Anyone who looks for, discovers or reports a vulnerability covered by this policy. No prior registration is required.
- Publisher
- Alexandre ETEOCLE, sole trader, publisher of the RackList platform and data controller within the meaning of the GDPR.
- Platform
- The racklist.eu website and only those services the publisher operates itself, as listed in article 3.
- Vulnerability
- A design, configuration or implementation flaw that makes it possible to undermine the confidentiality, integrity or availability of the platform or of the data it processes.
- Coordinated disclosure
- The process whereby the researcher informs the publisher first, allows the period set out in article 7 for a fix, and then publishes if they wish to.
Authorised scope
You are authorised to carry out non-destructive testing against the following, all operated by the publisher:
- The racklist.eu website and the subdomains operated by the publisher, including the member area, the hosting provider area and the administration interfaces reached with your own credentials.
- The public application programming interface of the platform, called with a key attached to your own account.
- The embeddable component distributed by the platform and meant to be integrated into third-party websites.
- The code running in your browser: templates, scripts, stylesheets, security headers, content security policy.
- Transactional emails sent by the platform to your own address, together with the sender verification mechanisms of the domain.
- Authentication, federated identity and session management flows, exercised against accounts you control.
Create your own accounts for testing. Where a check requires two separate accounts, for instance to exercise an access control between users, create both of them yourself.
Excluded scope
The following does not belong to the publisher or falls outside what it may authorise. It has no power to let you test any of it, and does not do so:
- The physical, hardware and network infrastructure carrying the service. The servers are operated by OVH SAS, whose own terms and reporting procedure apply. That infrastructure is shared: it carries services other than RackList, and testing against it reaches third parties unconnected to the platform.
- The third-party services the platform relies on, in particular the content delivery and protection network (Cloudflare, Inc.), the payment provider (Stripe Payments Europe Ltd.) and the federated identity providers (Google, GitHub, Discord and ClientXCMS, operated by clientxcms.com). Each runs its own reporting procedure, which is where such findings belong. Only how the platform integrates these services falls under this policy, never the services themselves.
- The websites, client areas and infrastructure of the hosting providers listed on RackList. A listed provider is neither a customer nor a processor of the publisher: being listed grants no testing authorisation of any kind.
- Community spaces hosted on third-party platforms, in particular the community Discord server.
- People: the team, contributors, users, staff of listed hosting providers, along with their personal accounts and devices.
- Premises, equipment and physical media.
Forbidden techniques
Whatever the scope, the following techniques are forbidden. Using them forfeits the benefit of article 8 and may amount to a criminal offence:
- Denial of service in every form: bandwidth saturation, exhaustion of application or database resources, mass request sending, load testing, uncoordinated brute-force campaigns.
- Social engineering aimed at the RackList team, its contributors, its users or the listed hosting providers: phishing, impersonation, phone pretexting, soliciting access or credentials.
- Any test touching another user's real data: reading, altering, deleting or tampering with an account, a review, a private message or a listing you do not control.
- Exfiltrating data beyond the strict minimum needed as proof. Stop as soon as the flaw is demonstrated: a few records or a truncated identifier are enough. Do not copy any database, do not download any dataset, keep nothing beyond the report.
- Installing a backdoor, an implant or a hidden account, and any action meant to retain access over time.
- Destroying, altering or encrypting data, degrading a service, visibly defacing the site.
- Aggressive automated scanning of production without prior coordination with the publisher.
How to report
Send your report by email to the address below. French and English are both accepted. You receive an acknowledgement within the period set out in article 7.
A usable report contains:
- A description of the vulnerability and of the affected component.
- The exact steps to reproduce it, in order.
- The impact as you assess it, and the worst case you can see.
- Minimal proof: a screenshot, a request, a truncated excerpt. Nothing more.
- The timestamps of your testing and the source addresses used, so we can tell your activity apart from a real attack.
- The name or handle you would like to be credited under, if you want credit at all.
The following is not a valid report: raw scanner output with no analysis and no demonstrated impact, a configuration deviation with no exploitable consequence, and a finding already covered by a report being handled.
No consideration may be demanded in exchange for a report, or as a condition of sending it. A payment demand made before the technical details are handed over is treated as an attempted extortion, not as a report, and forfeits the benefit of article 8.
You may, in parallel or instead, pass your information to the French national cybersecurity agency under article L. 2321-4 of the Code de la défense, which requires the agency to keep your identity confidential. That channel adds to ours rather than replacing it, and does not waive the rules of this policy.
Deadlines
The publisher is a small operation. The deadlines below are the ones it can genuinely meet; they are not decoration.
- Acknowledgement
- 5 working days from receipt of the report.
- Triage
- 15 working days: we tell you whether the vulnerability is accepted, the severity we assign to it and what we plan to do next.
- Fix
- 90 calendar days targeted for an accepted vulnerability. A critical, actively exploitable vulnerability is handled as a priority, without waiting for that deadline.
- Public disclosure
- You are free to publish once 90 calendar days have elapsed from the acknowledgement, whether or not a fix has shipped. We may ask you for a reasoned extension; we cannot impose one on you. Earlier publication by mutual agreement is possible as soon as the fix is deployed.
Our silence is not a refusal, but it does not bind you indefinitely. If no acknowledgement has reached you after 5 working days, chase us. After 30 calendar days with no reply at all from us, you are released from the coordination obligation and free to publish.
No-prosecution commitment
Testing carried out in full compliance with articles 3, 4, 5 and 6 is expressly authorised by the publisher. That is the essential point of this document: authorised access is not fraudulent access within the meaning of articles 323-1 and following of the French Criminal Code.
The authorization granted above is conditional on reporting. Any vulnerability you discover must be reported to us without undue delay, and no later than 72 hours after you found it. A longer delay is acceptable where the analysis genuinely requires it and you tell us so within that same window. Failing that, the authorization retroactively stops covering the tests concerned and the corresponding access becomes unauthorized again. Keeping, exploiting, passing on or selling an unreported vulnerability places its author outside this policy, whatever their initial intent.
Towards any researcher who complies with this policy, the publisher undertakes to file no criminal complaint, bring no civil action, seek no injunction or takedown, and request no sanction from a hosting provider, an internet access provider, a school or an employer, on the sole ground of their research or of their report.
Should a third party nonetheless bring an action against a researcher over work covered by this policy, the publisher undertakes to confirm in writing, at the researcher's request, that the work was authorised.
A minor deviation, committed in good faith and corrected at once, does not forfeit the benefit of this article. Overall conduct is what counts, not the letter. Doubt favours the researcher who reported rather than published.
This commitment covers what the publisher controls. It binds neither the third parties named in article 4, nor the courts, nor the public prosecutor, since criminal proceedings are not the publisher's to bring or to drop. It does not cover conduct falling under article 5, nor a report that comes with a demand for consideration.
Crediting the researcher
An accepted report entitles the researcher, at their choice:
- To public credit on the researcher recognition page, under the name or handle of your choosing.
- To full anonymity. That is the default: nothing is published about you without your agreement.
- To access to the RackList bug bounty programme, which opens a dedicated reporting channel and, where applicable, a reward described in that programme's own rules.
Public credit is only given once the fix has shipped, so as not to point at a flaw that is still open.
This policy creates no obligation to pay a financial reward. A report sent outside the bug bounty programme gives no entitlement to a bounty on the strength of this document alone.
Personal data encountered during your testing
If your testing exposes you, even unintentionally, to someone else's personal data, stop immediately, look at nothing beyond what proves the flaw exists, do not keep it, do not pass it to anyone, and say so in your report.
Delete every copy as soon as the publisher has acknowledged the report, and confirm that deletion in writing. Keeping such data beyond that point is no longer covered by this policy and falls under ordinary law.
The data you send us, your contact address, the content of the report and the technical details, is processed solely to triage and fix the issue, on the basis of the publisher's legitimate interest (GDPR art. 6(1)(f)), and kept for three years as evidence and for follow-up. Your rights are exercised as described in the Privacy policy.
Version and amendments
This policy is versioned. Its version and its last update date appear at the top of the page. The frame applying to a report is the version in force on the day it was sent: a later amendment cannot be held against you retroactively. Where an application to the bug bounty programme carries acceptance of this policy, the accepted version is kept with that application.
Governing law
This policy is governed by French law. It is read consistently with the platform Terms of Service. It waives none of the publisher's rights in respect of conduct outside the scope it defines, and gives no warranty on behalf of a third party. Any dispute over its interpretation or its performance is submitted to the courts having jurisdiction where the publisher is established.