We take the security of Brakka and our customers' data seriously. If you believe you have found a security vulnerability in one of our services, we would like to hear from you.
How to report
Email sikkerhet@brakka.no. We read reports in Norwegian and English. Our machine-readable contact details are published at brakka.no/.well-known/security.txt.
What to include
- Which service is affected and where (URL, app version, or API endpoint).
- Steps to reproduce the issue, with any request details or screenshots that help.
- What impact you believe the issue has.
- How we can reach you for follow-up questions.
What to expect from us
- An acknowledgement within 3 business days.
- Status updates while we investigate and fix the issue, until it is resolved.
- Credit for the finding if you want it, once a fix is in place. We do not currently run a bug bounty programme.
Please give us reasonable time to fix an issue before disclosing it publicly. We will agree on a timeline with you.
Scope
- The Brakka web application at brakka.no.
- The Brakka mobile apps published on the App Store and Google Play in Norway.
- The APIs that back the web application and the mobile apps.
Services run by third parties on our behalf, such as hosting and email providers, are out of scope — please report issues in those directly to the provider.
Safe harbor
We will not pursue legal action against researchers who act in good faith and within this policy. Good faith means that you only test systems in scope, stop and report as soon as you have confirmed a vulnerability, do not access, copy, modify, or delete data that is not your own beyond what is needed to demonstrate the issue, do not disrupt our services or degrade them for other users, and do not use social engineering, phishing, or physical attacks against our staff or customers. If we cannot tell whether your activity was in good faith, we will ask before doing anything else.