Security Policy

How to report security vulnerabilities in the Salvajes en la Vía platform

Scope

This security policy applies to all Salvajes en la Vía services, including:

  • Salvajes en la Vía (atulaa-test.movilidadbogota.gov.co/salvajes)
  • WhatsApp Chatbot

Reporting a Vulnerability

If you discover a security vulnerability, please report it responsibly:

What to Include in Your Report

Description of the vulnerability and its potential impact
Steps to reproduce the issue
Affected component (web platform or WhatsApp chatbot)
Any proof-of-concept code or screenshots
Your contact information for follow-up

Response Timeline

AcknowledgmentWithin 24 hours
Initial assessmentWithin 72 hours
Fix deploymentWithin 7-30 days

Responsible Disclosure Rules

Please DO NOT:

  • Access or modify other users' data
  • Perform denial of service attacks
  • Send spam or social engineering attacks to our users
  • Publicly disclose the vulnerability before it's fixed
  • Use automated scanning tools without permission

We will not pursue legal action against researchers who follow these guidelines and report vulnerabilities responsibly.