Start building with AI in minutes.
Read more
Choose how you'd like to reach us
This policy explains where to send a security report, what happens after we receive it, and the protections that apply when you research in good faith.
Last revised: 15 August 2026We want to make sure you have all the information you need. While we provide translations of our legal agreements and policies for your ease, please keep in mind that the English version is the official and most accurate one. Translations are just here to help you read and understand better, but they don’t have any legal weight. If there’s ever a misunderstanding, the English version will be the one that counts.
1.1 Purpose. Pladinum Group SL (“Pladinum”, “we”, “us”, “our”) welcomes reports of security vulnerabilities from researchers and members of the public. This policy explains how to report a vulnerability in our systems, what you can expect from us in return, and the rules that apply.
1.2 Our commitment. We take security seriously and treat every good-faith report as a priority. This is a vulnerability disclosure policy, not a paid bug bounty program, and we currently offer recognition rather than monetary rewards (see Section 7).
2.1 In scope. This policy covers systems operated by Pladinum, including the Pladinum website (pladinum.com), our customer billing and control panel, our mail infrastructure, and our DNS infrastructure.
2.2 Out of scope. The following are not covered by this policy: websites, applications, and content hosted by our customers on our infrastructure (report these to the customer concerned, or to abuse@pladinum.com if the content is illegal, see our Acceptable Use Policy); third-party services and platforms we do not operate; and the testing methods listed in Section 4.
3.1 Where. Send your report by email to security@pladinum.com.
3.2 What to include. A clear description of the vulnerability, the affected system or URL, the steps required to reproduce it, and any proof-of-concept material. Please provide enough detail for us to reproduce and verify the issue.
3.3 Language. We accept reports in English or Spanish.
4.1 Good faith. Act in good faith, avoid privacy violations, data destruction, and service disruption, and interact only with accounts that you own or have explicit permission to test.
4.2 Data. Do not access, modify, or store more data than is necessary to demonstrate a vulnerability. If you encounter personal data, stop, do not retain it, and tell us in your report.
4.3 Prohibited testing. Do not perform denial-of-service or volumetric testing, social engineering of our staff or customers, physical attacks, spam, or automated scanning that degrades our services.
4.4 No early disclosure. Do not disclose the vulnerability publicly or to any third party until we have resolved it and agreed disclosure with you (see Section 6).
5.1 Acknowledgement. We aim to acknowledge your report within five (5) business days.
5.2 Assessment. We will investigate and validate the report and keep you informed of our progress and the expected timeline for a fix.
5.3 Resolution. We will work to remediate confirmed vulnerabilities as quickly as is practical, prioritising by severity.
6.1 We follow a coordinated disclosure approach. We ask that you allow us up to ninety (90) days from the date of your report to remediate a vulnerability before any public disclosure, and that any disclosure be agreed with us in advance. We are glad to extend or shorten this window by mutual agreement depending on the severity and complexity of the issue.
7.1 We do not currently operate a paid bug bounty program. With your consent, we are glad to publicly credit researchers who responsibly report valid vulnerabilities. We may introduce a formal rewards program in the future; should we move to a managed platform, we intend to use an EU-based provider, consistent with our data protection commitments.
8.1 If you make a good-faith effort to comply with this policy during your research, we will consider your actions authorised, we will not pursue or support legal action against you in connection with your report, and we will work with you to understand and resolve the issue quickly. This safe harbour does not apply to actions that violate this policy or applicable law.
9.1 This policy does not grant permission to act in any way that is inconsistent with the law. It is governed by the laws of Spain and should be read together with our Terms and Conditions and our Acceptable Use Policy. Nothing in this policy creates contractual obligations or waives any of Pladinum’s rights, except the safe harbour expressly stated in Section 8.
To report a security vulnerability, or for questions about this policy, contact us:
Pladinum Group SL
Avenida de Manolete 3a
29660 Marbella, Malaga (ES)
Security reports: security@pladinum.com
Abuse / illegal content: abuse@pladinum.com
Telephone: +34 697 9898 40
Website: www.pladinum.com