Security policy

Version 1.0 · Last updated: May 4, 2026 · Operator: eleata

Reporting a vulnerability

If you believe you have found a security vulnerability in the eleata Peppol API, the SDKs, or the GitHub Action, please report it to security@eleata.io. We aim to acknowledge reports within 2 business days and to provide a remediation timeline within 5 business days.

What to include

Coordinated disclosure

We follow a coordinated-disclosure model. We ask researchers to give us a reasonable opportunity to remediate before publicly disclosing the vulnerability. We commit to:

Out of scope

Bug bounty

We do not currently operate a paid bug-bounty programme but may award discretionary thanks and credit for material findings.

Security controls in place

Hall of fame

We will list responsible researchers here once the programme has its first valid reports.