Security

We take the security of your data and our service seriously. This page lists the technical safeguards in place and explains how to report a vulnerability if you find one.

Independently verified

The public surfaces of vaapadcapital.com are configured against modern web-security baselines. The badges below link to independent third-party scanners — click any of them to verify our current grade live with the issuing scanner. We do not host or cache these scores.

TLS & Certificate A+ SSL Labs HTTP Headers A+ securityheaders.com Web Security Posture View Mozilla Observatory Comprehensive Audit View Hardenize Modern Web Standards View Internet.nl HSTS Status View hstspreload.org Certificate Transparency View crt.sh

What this protects

Reporting a vulnerability

If you have discovered a security issue affecting any of our services, we want to hear from you. Please do not disclose it publicly until we have had a chance to investigate and remediate.

Contact: [email protected]
Response time: We aim to acknowledge reports within 48 hours.

Machine-readable contact information following RFC 9116 is also available.

Scope

Out of scope

Safe harbor

Good-faith research conducted in accordance with this policy will not result in legal action from us. Please do not access, modify, or delete data belonging to other users; stop testing as soon as you can confirm an issue and report it.

Acknowledgements

No reports yet. If you are the first to responsibly disclose a finding, you will be credited here with your permission.

← back to home