شركة أمن البيانات للأمن السيبراني

DataSec — Zero Trust SecurityRequest a consultation

Responsible disclosure

Responsible disclosure

We value the work of security researchers. If you discover a vulnerability in one of our web properties, report it responsibly and we will treat it seriously.

Last updated: 27 September 2026

Scope

This policy covers the web properties DataSec operates on the datasec.sa domain and its subdomains, including the public website, its forms and the careers portal.

It does not cover our clients' systems, systems we manage on behalf of clients under contract, or third-party services we use (such as hosting and email providers). If you find a vulnerability in a third-party service, report it to that party directly.

How to report

Send your report to info@datasec.sa. The same contact is published in our security.txt file at /.well-known/security.txt. We accept reports in Arabic or English.

A good report helps us verify quickly. Please include:

  • The affected page or service and the type of vulnerability.
  • Detailed reproduction steps, with relevant requests and responses or screenshots.
  • The potential impact as you assess it.
  • Any special tools or configuration you used.
  • How we can contact you for follow-up, and whether you want to be credited when the issue is fixed.

Do not include other people's personal data or content extracted from our systems in the report; a description of what you were able to reach is enough.

Rules for good-faith research

We consider research to be in good faith if you:

  • Stop as soon as the vulnerability is demonstrated, without expanding access or extracting or modifying data.
  • Do not access data that is not yours, and if that happens accidentally, stop, tell us and delete what you hold.
  • Do not disrupt the service or degrade the experience of other users.
  • Use only your own accounts and data for testing.
  • Do not disclose the vulnerability publicly before we have fixed it and agreed disclosure with you.
  • Do not demand payment as a condition of reporting or of withholding disclosure.

Safe harbour

If you follow this policy, we consider your research authorised, we will not take legal action against you because of it and we will work with you to understand and resolve the issue. We cannot give this undertaking on behalf of third parties or law-enforcement authorities, but we will not initiate any complaint against research that followed the rules above.

Out of scope

The following are outside this policy and are not considered authorised research:

  • Denial-of-service attacks or any testing that loads or disrupts the service.
  • Social engineering or phishing directed at our staff, clients or partners.
  • Physical access to our premises or devices.
  • High-volume automated scanning that generates large request volumes.
  • Automated tool output without proof of actual impact.
  • Vulnerabilities in third-party services or in client systems.
  • Issues that depend on an outdated, unsupported browser or operating system.

What to expect from us

  • We confirm receipt of your report and tell you who is handling it.
  • We verify the report, work on remediation according to severity and keep you informed when there is progress.
  • After the fix, we agree the timing of any disclosure you wish to make and credit you as thanks if you want that.

This policy sets no binding timelines and we do not run a monetary bounty programme. We treat every report seriously regardless.