Security

ARMITAS a.s. takes the security of its products, services, and website seriously. If you have discovered a security vulnerability related to any of our products (ARM Analytics & Intelligence, ARM DataGraph Editor), our website, or another service we operate, we would appreciate you letting us know.

Contact

Please report vulnerabilities to: vulnerabilities@armitas.sk

This address is dedicated exclusively to reporting security vulnerabilities. For other questions, please use our regular contact info@armitas.sk

What you can report

We welcome reports concerning in particular:

the armitas.sk website

the ARM Analytics & Intelligence and ARM DataGraph Editor products

other online services and systems operated by ARMITAS a.s.

How to report

To help us assess and fix the vulnerability as quickly as possible, please include in your report:

a brief description of the vulnerability and its potential impact

steps to reproduce it (including a screenshot or PoC, if available)

the type and version of the affected product/service

your contact details for any follow-up questions

What you can expect

We will acknowledge your report within 5 business days.

We will keep you informed of progress.

Once the vulnerability has been fixed, we will be happy to agree with you on the timing and manner of disclosure (coordinated disclosure).

Responsible disclosure principles

When testing and reporting vulnerabilities, we ask that you:

act in good faith and avoid causing harm to us or third parties

do not access data beyond what is necessary to demonstrate the vulnerability, and do not modify or delete data that is not yours

do not perform DoS/DDoS attacks, social engineering against our employees, or physical attacks on our premises or infrastructure

give us reasonable time to fix the vulnerability before any public disclosure

If you act in accordance with these principles and in good faith, we will not pursue legal action against you in connection with your report.


This procedure forms part of compliance with the requirements of Regulation (EU) 2024/2847 (Cyber Resilience Act) regarding a single point of contact for reporting vulnerabilities.

ARMITAS, a.s.