Snapshot 74472
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Vulnerability Disclosure Program (VDP) DataArt values the cybersecurity research community and welcomes responsible reports that help us protect our systems, customers, and data. If you discover a security vulnerability in a public-facing system or resource owned, operated, or controlled by DataArt, please report it promptly so we can investigate and fix it. By submitting a vulnerability report to DataArt, you confirm that you have read and accepted the terms below. Let’s work together to keep our digital ecosystem secure. Terms and Conditions For the purposes of this Program, “researcher” means an external individual or legal entity acting in good faith who discovers, identifies, tests, or reports a potential security vulnerability in a public-facing system or resource owned, operated, or controlled by DataArt in accordance with this Program. Researchers must act in good faith and follow these rules: Do not execute or attempt any DoS/DDoS attacks, stress tests, or actions that may degrade availability. Do not deploy, upload, execute, or store malware on DataArt assets. Do not run tests that send spam or unsolicited messages (e.g., email/SMS flooding, mass form submissions). Do not perform any high-volume automated scanning or automated testing. Do not test in a way that disrupts services, corrupts data, or impacts other users. No physical security testing and no social engineering (phishing, impersonation, pretexting, etc.). Minimize data access and collection to what is strictly necessary to validate and report the vulnerability. If you accidentally access confidential, personal or proprietary data, stop immediately and notify us. Delete any confidential, personal or proprietary data inadvertently obtained during testing once the report is submitted and confirmed as received. Do not access, copy, retain, use, or publicly disclose any confidential, personal or proprietary information beyond what is strictly necessary to report the vulnerability. Safe Harbor DataArt considers security research conducted in good faith and in accordance with this Program’s Terms and Conditions, and limited to public-facing systems or resources that DataArt is authorized to include in this Program, to be authorized. Accordingly, DataArt will not pursue civil legal action against researchers who make a good-faith effort to comply with these Terms and Conditions, and will not refer them to law enforcement or regulatory authorities, unless such referral or cooperation is required by applicable law, regulation, court order, or binding legal obligation. This Safe Harbor does not apply to conduct that: (a) is outside the scope defined in this Program; (b) involves extortion, coercion, or threats; (c) involves accessing, retaining, or disclosing data beyond what is strictly necessary to demonstrate the vulnerability; (d) involves public disclosure without DataArt’s prior written approval; or (e) otherwise fails to meet the good-faith standard described above. DataArt reserves sole discretion to determine whether research was conducted in good faith and in accordance with this Program. If a third party initiates or threatens legal action related to research conducted in accordance with this Program, DataArt may, at its discretion and subject to applicable law and confidentiality obligations, confirm to that third party the facts known to DataArt regarding the researcher’s compliance with this Program, including any involvement of law enforcement or regulatory authorities. This Safe Harbor does not bind third parties or guarantee the outcome of any third-party action; it reflects DataArt’s own commitment and does not require DataArt to provide legal representation or other assistance to the researcher. Informational Findings The following are generally considered Informational - we may acknowledge them, but won't prioritize reports limited to these issues unless they're part of a chain with demonstrable impact: Missing security headers or cookie flags (CSP, HSTS, Secure/HttpOnly/SameSite, etc.) without a working exploit. SSL/TLS weaknesses (weak ciphers, legacy protocol support) without a proof of concept. SPF/DKIM/DMARC misconfigurations. Missing rate limiting or CAPTCHA, absent a concrete impact. Self-XSS, low-impact CSRF (login/logout), and clickjacking on non-sensitive pages. Information disclosure of versions, banners, stack traces, or user/email enumeration without further impact. Raw output from automated scanners without manually validated impact. Theoretical, best-practice, or compliance-style findings. Issues requiring physical access, a rooted/jailbroken device, EOL software, or an already-compromised account. Response Process After receiving your report, the DataArt Security Team will triage and investigate it. If confirmed, we will take corrective actions to mitigate the risk and may contact you for clarifications. This Program follows responsible disclosure principles and does not provide financial rewards, unless explicitly stated. DataArt does not guarantee any specific response time, remediation timeline, acknowledgement, public recognition, or other benefits. Legal By submitting a report, you confirm that you are authorized to submit it and grant DataArt the right to use, reproduce, and share the submission as reasonably necessary for investigation and remediation. You also agree not to publicly disclose the report or related vulnerability details, or use DataArt’s name or trademarks in relation to the report without DataArt’s prior written approval. Processing of personal data By submitting a report, you agree that DataArt may process the personal data you provide (such as your name and email address) solely for the purpose of investigating and resolving the reported vulnerability and for back communication regarding your submission. Your data will be retained only as long as necessary and will not be shared with third parties except as required by law. You may request access to, correction of, or deletion of your data at any time by contacting privacy@dataart.com. Report to DataArt In the description field, please include as much detail as possible: The affected URL, endpoint, or system. Steps to reproduce the issue. What an attacker could achieve by exploiting it. Date and time of testing. If you have screenshots or other supporting evidence, you may include a link to a file-sharing location where the materials are stored. Please make sure the link is accessible to DataArt. Do not include passwords, one-time codes, full payment card numbers, or other secrets in the form. Suspected fraud, fake job offers, or misuse of DataArt branding are reported through the Fraud Awareness page. Company About Us Team Privacy Policy Company Presentation Modern Slavery Statement Press Kit Legal Information Services DataArt Solution Advisors Custom Software Engineering Security Managed Services & Support Legacy Modernization Quality and Performance Engineering AI and ML Cloud Blockchain Data and Analytics DevOps Industries Finance Travel Tech Solutions Media & Entertainment Healthcare & Life Sciences Retail & Distribution Education Insights Clients Contact Us Anonymous Report Sustainability Report New York +1 (212) 378-4108New-York@dataart.com London +44 (0) 20 7099 9464uk-sales@dataart.com Zug +41 (0) 415880158ch-sales@dataart.com Munich +49 (89) 745 390 23DE-Sales@dataart.com All locations By using our site, you acknowledge that you have read and understand our Privacy and Cookie Policy. All trademarks listed on this website are the property of their respective owners. All rights reserved. Copyright © 2026 DataArt Fraud AwarenessVulnerability Disclosure