
Security
ARMITAS a.s. takes the security of its products, services, and website seriously. If you have discovered a security vulnerability related to any of our products (ARM Analytics & Intelligence, ARM DataGraph Editor), our website, or another service we operate, we would appreciate you letting us know.
Contact
Please report vulnerabilities to: vulnerabilities@armitas.sk
This address is dedicated exclusively to reporting security vulnerabilities. For other questions, please use our regular contact info@armitas.sk
What you can report
We welcome reports concerning in particular:
the armitas.sk website
the ARM Analytics & Intelligence and ARM DataGraph Editor products
other online services and systems operated by ARMITAS a.s.
How to report
To help us assess and fix the vulnerability as quickly as possible, please include in your report:
a brief description of the vulnerability and its potential impact
steps to reproduce it (including a screenshot or PoC, if available)
the type and version of the affected product/service
your contact details for any follow-up questions
What you can expect
We will acknowledge your report within 5 business days.
We will keep you informed of progress.
Once the vulnerability has been fixed, we will be happy to agree with you on the timing and manner of disclosure (coordinated disclosure).
Responsible disclosure principles
When testing and reporting vulnerabilities, we ask that you:
act in good faith and avoid causing harm to us or third parties
do not access data beyond what is necessary to demonstrate the vulnerability, and do not modify or delete data that is not yours
do not perform DoS/DDoS attacks, social engineering against our employees, or physical attacks on our premises or infrastructure
give us reasonable time to fix the vulnerability before any public disclosure
If you act in accordance with these principles and in good faith, we will not pursue legal action against you in connection with your report.
This procedure forms part of compliance with the requirements of Regulation (EU) 2024/2847 (Cyber Resilience Act) regarding a single point of contact for reporting vulnerabilities.
ARMITAS, a.s.