Vulnerability disclosure policy

Version 2026-09-10 · effective 2026-09-10

If you have found a security problem in Titan Community, we want to hear about it. This page explains how to report it and what we will do.

How to report

Email [email protected] with enough detail to reproduce the issue: the affected URL or component, the steps you took, and what you observed. Screenshots or a short proof of concept help. Please write in English or Czech.

We will acknowledge your report within 3 working days and tell you what we intend to do about it. We will keep you informed while we work on a fix, and we are happy to credit you when it ships if you would like that.

What we ask

  • Give us a reasonable opportunity to fix the issue before you disclose it publicly.
  • Use only accounts and data that belong to you. Do not access, modify or delete other people's tickets, applications or accounts.
  • Do not run denial-of-service tests, automated scanners against production, spam, social engineering or physical attacks.
  • Stop as soon as you have demonstrated the problem, and tell us instead of going further.

We do not currently run a paid bug bounty. We will not pursue legal action against researchers who follow this policy in good faith.

Out of scope

Findings against Discord, Stripe or our hosting provider belong to those companies — please report them through their own programmes. Missing best-practice headers, version-disclosure banners and issues that require a compromised device or a man-in-the-middle position are usually out of scope unless you can show real impact.

If customer data was affected

Where a security incident affects personal data, Titan Software z.s. notifies the Czech supervisory authority within 72 hours of becoming aware of it where the incident is notifiable, and informs affected customers as required by Articles 33 and 34 GDPR. If your report shows that data was actually exposed, say so clearly — it changes how quickly we have to act.