Legal
Vulnerability Disclosure Policy
Effective and last updated: 30 July 2026. Published by Clicked IN FZE LLC.
Scope
This policy covers the Sitrava website at sitrava.online. There is no Sitrava application, customer account system or production service in scope at this time.
How to report
Email management@sitrava.online with a description of the issue and the steps needed to reproduce it. Please do not include personal data belonging to other people.
Testing boundaries
Please do not attempt denial-of-service testing, social engineering, physical intrusion, or any testing that degrades the website or accesses data belonging to others.
Coordinated disclosure
Sitrava asks reporters to allow reasonable time for investigation and remediation before public disclosure, and will coordinate timing with the reporter where possible.
Rewards
Sitrava does not operate a paid bug-bounty programme. Recognition may be offered case by case.
Good faith
Sitrava will not pursue researchers who report in good faith and stay within the boundaries above. This does not authorise activity that breaks applicable law or infringes third-party rights.