Legal

Vulnerability Disclosure Policy

Effective and last updated: 30 July 2026. Published by Clicked IN FZE LLC.

Scope

This policy covers the Sitrava website at sitrava.online. There is no Sitrava application, customer account system or production service in scope at this time.

How to report

Email management@sitrava.online with a description of the issue and the steps needed to reproduce it. Please do not include personal data belonging to other people.

Testing boundaries

Please do not attempt denial-of-service testing, social engineering, physical intrusion, or any testing that degrades the website or accesses data belonging to others.

Coordinated disclosure

Sitrava asks reporters to allow reasonable time for investigation and remediation before public disclosure, and will coordinate timing with the reporter where possible.

Rewards

Sitrava does not operate a paid bug-bounty programme. Recognition may be offered case by case.

Good faith

Sitrava will not pursue researchers who report in good faith and stay within the boundaries above. This does not authorise activity that breaks applicable law or infringes third-party rights.