Reporting a vulnerability
Last updated: 31 July 2026
1. How to reach us
If you have found a vulnerability in SedeClick, email security@sedeclick.com. Tell us what you found, how to reproduce it, and what impact you think it has. Plain text is fine — there is no form to fill in.
We will reply within a reasonable time and keep you posted while we work on a fix.
2. What we ask of you
We handle migrants' personal documents: passports, immigration status, case files. Please do not access data that is not yours, do not download or keep it, and stop as soon as you have confirmed the flaw exists.
No denial-of-service testing, no social engineering against our staff or the gestorías we serve, and nothing that degrades the service for real users.
Please give us reasonable time to fix the issue before disclosing it publicly.
3. What we offer
We do not run a bug bounty programme. If you research in good faith and respect the above, we will not pursue legal action over it.
We are happy to credit you publicly once the issue is fixed, if you would like that.
4. Out of scope
Automated scanner output with no demonstrated impact, missing headers that do not lead to an actual flaw, software version numbers without an exploitable vulnerability, and issues in third-party services we do not operate (please report those to the provider directly).
security@sedeclick.com