# Online Auctions24 — security contact and disclosure policy. # # If you have found a vulnerability in this platform, please write to the # address below before disclosing it publicly. Include the URL or endpoint, # what you did, and what you observed. A proof of concept helps; please keep # it to the minimum needed to demonstrate the issue. # # We aim to acknowledge a report within one business day (Kigali time, # CAT/UTC+2) and to tell you our assessment and intended fix within five. # # Please do NOT, at any point: place or alter bids, access an account that is # not yours, modify or delete auction data, or run load or denial-of-service # tests. This platform runs online auctions for real money, and a lot that # closes wrongly cannot be un-closed. If demonstrating an issue would require # any of those, describe it instead and we will arrange a test environment. # # We do not currently operate a paid bounty. We will credit you by name in # the fix notes if you would like that. Contact: mailto:security@onlineauctions24.com Expires: 2027-08-31T23:59:59.000Z Preferred-Languages: en Canonical: https://www.onlineauctions24.com/.well-known/security.txt