Responsible Disclosure
How to report a security vulnerability to Viaris: scope, reporting channel, what we commit to, and what we ask of you.
- Last reviewed
- 24 May 2026
In brief
- Report a vulnerability in one structured email via the Contact page; the in-scope surface is the Viaris domains, their build output and the cookie-consent flow, in six languages.
- Viaris acknowledges within 5 business days, triages severity, and asks for a ~90-day window before public disclosure; there is no paid bug-bounty, only public credit.
- Good-faith research that follows this policy is treated as authorised for computer-misuse purposes to the extent Viaris can legally grant it.
We welcome security research that helps keep Viaris safe for readers. This page sets out the rules of engagement so a good-faith reporter has clear expectations.
1. Scope
In scope:
-
Viaris.eu,Viaris.be,viaris.euand any subdomain serving production content. - The static-site build output: HTML, CSS, JS bundles, the structured data we emit.
- The cookie consent flow and the consent storage on the client.
Out of scope:
- Third-party operator websites (ASFINAG, DARS, NÚSZ, BGTOLL, etc.) — please report to those operators directly.
- Issues that require a privileged position (already-compromised browser, malicious browser extension, physical access to the user's device).
- Automated-scanner output without a clear, demonstrable security impact.
- Reports about missing best practices (HTTP headers, TLS settings) where no exploitable risk has been shown.
2. How to report
Send a single, structured report to the security contact listed on the Contact page. A useful report includes:
- a short description of the issue and the affected URL or component;
- step-by-step reproduction, including the request payload if relevant;
- the impact you believe the issue has, and a realistic exploitation scenario;
- the date and time of testing and the browser or tool used.
You can submit reports in English, French, German, Dutch, Romanian or Polish.
3. What we commit to
- Acknowledge your report within 5 business days.
- Confirm whether the issue is in scope and triage its severity.
- Keep you informed of remediation progress on material findings.
- Credit you publicly once a fix is shipped, if you wish.
4. What we ask of you
- Do not access, modify, or download data that does not belong to you. If a misconfiguration exposes someone else's data, stop and tell us — do not download more than the minimum needed to evidence the issue.
- Do not perform denial-of-service tests, social engineering against staff, or attacks against physical premises.
- Give us a reasonable window to fix the issue before publishing details. We aim for 90 days as a default, shorter if the fix is trivial and the risk is high.
- Operate in good faith. Reports submitted with the genuine intent of improving security are welcome; threats or demands for payment in exchange for non-disclosure are not.
5. Safe harbor
If you research in good faith, follow this policy, and report what you find, we will not pursue legal action against you for that research, and we will treat your conduct as authorized for the purposes of relevant computer-misuse statutes — to the extent we can legally provide such authorization.
6. No bounty (yet)
We do not currently run a paid bug-bounty program. Recognition is via public credit and direct correspondence. If that changes, the offer will be published here.