Trust Center
// coordinated vulnerability disclosure

Vulnerability disclosure policy.

We welcome good-faith security research that helps us protect Argus, Kotav Labs and our customers. This policy defines the authorization and safeguards that apply.

Effective 14 September 2026Preferred language: English or Portuguese
// authorized scope

Good-faith testing of Kotav-operated services.

This policy authorizes research on publicly reachable services operated by Kotav Labs under kotavlabs.com and its subdomains, provided the research follows every condition below. It does not authorize testing of systems merely assessed, monitored or referenced by Argus.

// researcher obligations

Keep the work proportionate and private.

  • Use the minimum interaction and data access needed to demonstrate the issue.
  • Stop immediately if you encounter customer data, secrets, personal data or evidence of an active compromise.
  • Do not download, retain, alter or disclose data that is not yours. Include redacted evidence in your report.
  • Report promptly and keep the issue confidential while we investigate and remediate it.
  • Comply with applicable law and do not degrade service availability or privacy.
// excluded activity

The following activity is not authorized.

  • Customer systems, assessment targets, customer data and any tenant that you do not own
  • Third-party services, suppliers and infrastructure not operated by Kotav Labs
  • Denial of service, destructive testing, malware, persistence or data alteration
  • Social engineering, physical attacks, credential stuffing and automated login abuse
  • Accessing more data than is strictly necessary to demonstrate a vulnerability
// safe harbour

Protection for compliant research.

If you act in good faith and comply with this policy, Kotav Labs will treat your research as authorized, will not initiate or recommend legal action against you for that research, and will work with you to understand and resolve the issue. If a third party initiates legal action, we will make it clear where your work complied with this policy. We cannot authorize research on third-party systems or bind third parties.

// coordinated disclosure and CVEs

We coordinate before publication.

Please allow a reasonable remediation period before public disclosure, normally up to 90 days after validation unless we agree otherwise or active exploitation materially changes the risk. Kotav Labs will seek a CVE for confirmed high or critical product vulnerabilities that require customer action or show active exploitation, and will include accurate CWE and CPE information where applicable. Submission of a report does not create an entitlement to payment; no bug bounty is currently offered.

Cloud Security Alliance AI Trustworthy Pledge 2026Kotav Labs STAR Level 1 CAIQ self-assessment in the CSA STAR RegistryKotav Labs STAR for AI Level 1 self-assessment in the CSA STAR RegistryKotav Labs featured in the Cloud Security Alliance Startup ShowcaseGreen Web Foundation verified green hosting for kotavlabs.com
Kotav Labs internal ISO/IEC 27001:2022 ISMS programme statusKotav Labs ISO/IEC 42001:2023 internal readiness programme — not certifiedKotav Labs internal NIS2 implementation statusKotav Labs internal QNRCS self-assessment statusKotav Labs internal CIS Controls 8.1 self-assessment statusKotav Labs internal NIST CSF and AI RMF framework statusKotav Labs internal OWASP ASVS and SAMM methodology status
Plano de Recuperação e Resiliência, República Portuguesa e Financiado pela União Europeia — NextGenerationEU