Disclosure policy
If you find a vulnerability in anything we run, tell us. We will not pursue legal action against good-faith research that follows these rules.
- Email
security@atalaia.review, encrypted with our PGP key if you can. - Give us reasonable time to fix before you publish. We aim to reply within 3 working days.
- Don't access, change or keep data that isn't yours, and stop as soon as you've shown the issue.
- No denial-of-service, social engineering or physical testing.
We credit researchers who want it, once the issue is fixed.
security.txt
Published at /.well-known/security.txt (RFC 9116):
Contact: mailto:security@atalaia.review Encryption: https://atalaia.review/pgp-key.txt Expires: 2027-10-08T00:00:00.000Z Preferred-Languages: en, pt, es Canonical: https://atalaia.review/.well-known/security.txt Policy: https://atalaia.review/trust/#disclosure
PGP key
Our public key is at /pgp-key.txt (Ed25519, valid until October 2028).
Fingerprint: 1D30 A03E AFEC 3C72 077B 2F27 346E 0437 30FF A362. Check it against a second channel before you trust it.
Privacy
This site does not track you. When you contact us, we keep your name, email and message only to answer you and run the engagement, and we delete them when they're no longer needed. You can ask for a copy or for deletion at any time: security@atalaia.review.
Client data from engagements stays in client systems wherever possible. When we must hold it, it is encrypted, access is limited to the people on the engagement, and it is deleted at the end.
No cookies
No analytics, no trackers, no cookies, so no cookie banner. Fonts are served from this site, so your browser makes no third-party requests.
Subprocessors
| Category | Purpose | Provider |
|---|---|---|
| Hosting | Serving this website | Cloudflare |
| Answering messages | Cloudflare (routing), Google (inbox) | |
| Scheduling | Booking calls | To be listed at launch |
We will announce changes here before they take effect.