Vulnerability disclosure policy
Last updated: August 6, 2026
1. Introduction
SYNIAPS SAS (24 Traverse Capron, 13012 Marseille, France, SIREN 991709890) is committed to protecting the data its customers entrust to it. This policy explains to security researchers how to conduct vulnerability discovery activities on our systems and how to report their findings to us: what is in scope, how to send a report, and the delay we ask for before any publication.
Reports from the security community are welcome, including anonymously.
2. Rules of conduct
We ask you to:
- notify us as soon as possible after discovering a real or potential security issue;
- give us a reasonable delay to fix the issue before any public disclosure, by default at least 90 days from our acknowledgment of receipt;
- make every effort to avoid privacy violations, service degradation, disruption of production systems and the destruction or manipulation of data;
- only use an exploit to the extent necessary to confirm the existence of the vulnerability, never to access data, establish persistence or pivot to other systems;
- stop testing immediately, notify us and maintain strict confidentiality as soon as you establish that a vulnerability exists or you encounter sensitive data (personal data, financial information, credentials, proprietary information of a third party);
- only use test accounts that belong to you, without ever accessing a customer's data;
- avoid mass submissions of low-quality reports.
3. Authorization
Research conducted in accordance with this policy is authorized. We will work with you to understand and quickly fix the issue, and SYNIAPS SAS will neither initiate nor support any legal action against you in connection with this research. This authorization does not cover activities that violate this policy, in particular any access to a customer's or a third party's data.
4. Scope
This policy applies to the following families of services:
- syniaps.fr and its public pages;
- the Syniaps web application, served on app.syniaps.fr;
- the applications and sites hosted for our customers under syniaps-apps.fr, for infrastructure-level issues only;
- the former domain cockpit-ia.fr, which now only redirects to syniaps.fr.
Anything not listed above, including any other subdomain of the domains mentioned, is out of scope and must not be tested. Vulnerabilities in third-party services Syniaps relies on are not covered by this policy: report them directly to the vendor concerned according to its own disclosure policy. If in doubt about the scope, write to us before starting.
Customer content is out of scope. Our customers' files, mailboxes and business data must never be accessed, even if a vulnerability allowed it.
5. Unauthorized testing
- denial of service (DoS/DDoS) and any test whose purpose or likely effect is to degrade availability;
- automated scans at a rate that affects service availability for customers;
- physical testing (access to premises), social engineering (phishing, vishing) targeting our teams, customers or providers, and any other non-technical testing;
- spam and attempts to compromise accounts that do not belong to you.
6. Reporting a vulnerability
Send your report by email to [email protected]. Anonymous reports are accepted. We acknowledge receipt within three business days and keep you informed of confirmation and remediation.
To help us process your report, include if possible:
- a description of the vulnerability and its class;
- the exact location: URL, endpoint or parameter;
- the potential impact;
- the reproduction steps (scripts, requests, screenshots where applicable);
- the date, time and source address of your tests, to correlate with our logs.
Reports in French as well as in English are welcome.
7. Our commitment
If you leave us a way to contact you, we commit to communicating transparently: acknowledgment of receipt within three business days, information on confirmation and remediation, and notification when the fix is deployed. With your agreement, we can credit you publicly once the issue is resolved. Syniaps does not operate a paid bug bounty program to date; reports are handled on their merits regardless.