Last updated: 2026-09-14
Security
Security contact: security@digitalfreedom.co.za · reporting form: https://security.digitalfreedom.co.za · machine-readable: /.well-known/security.txt
Provider: DigitalFreedom — a brand of DigitalFreedom Global LLC, 30 N Gould St, Ste N, Sheridan, WY 82801, United States
1. Introduction
Snapshots is software with digital elements, and the security of the people who use it is a priority. This policy sets out how anyone — a security researcher, a player, or a passer-by who noticed something — reports a suspected vulnerability, and how we handle the report under a coordinated vulnerability disclosure process.
It is written to satisfy, as a baseline:
- the EU Cyber Resilience Act (Regulation (EU) 2024/2847), in particular the manufacturer’s duty to operate a coordinated vulnerability disclosure policy and a single point of contact for reports;
- ISO/IEC 29147 (vulnerability disclosure) and ISO/IEC 30111 (vulnerability handling);
- CISA coordinated-disclosure practice and the good-faith security-research framing in US Department of Justice charging policy under the Computer Fraud and Abuse Act;
- generally recognised responsible-disclosure practice in Germany.
2. Scope
In scope:
- the Snapshots iOS app published under the DigitalFreedom brand;
- the Snapshots backend and its API at
snapshot.prod.app.digitalfreedom.co.za; - this website,
snapshots-quiz.app.
Out of scope: platforms, stores, hosting providers and dependencies we do not operate — report those to their operator. We will coordinate with such a party where the issue affects Snapshots. Also out of scope: findings without a security impact (missing hardening headers on a static site with no session, version banners, self-XSS, reports produced solely by an automated scanner and not verified).
3. How to report
Please include, where you can: the affected product, service or URL and the version; a description of the vulnerability and its impact; steps to reproduce, including any proof of concept; your severity assessment; and how you would like to be credited, if at all.
Reports may be written in English or German. Please include no more personal or third-party data than is strictly necessary to demonstrate the issue.
4. What we commit to
- Acknowledgement without undue delay — target: within 3 business days.
- Triage and validation, with a severity assessment.
- Status updates at meaningful progress, and notice when a fix or mitigation ships.
- Remediation of confirmed vulnerabilities in a reasonable, risk-based timeframe, worst first.
- Coordinated disclosure: we prefer public disclosure once a fix is available and users have had a reasonable chance to update, and we agree timing with you where practical.
- Where the Cyber Resilience Act or other law requires notification of an actively exploited vulnerability or a severe incident to the competent authority — the designated CSIRT coordinator and ENISA — we make those notifications within the statutory deadlines, independently of public disclosure.
5. Safe harbour
We will not initiate or support legal action against you for security research and vulnerability reporting carried out in good faith and in line with this policy. We consider such activity authorised access, and will not treat it as a breach of our terms of service, of anti-circumvention rules, or of computer-misuse law including the CFAA and its equivalents elsewhere.
The safe harbour applies while you keep to the rules in § 6. If a third party brings action against you for activity conducted in compliance with this policy, we will take reasonable steps to make known that your actions were authorised.
6. Rules of engagement
- Make a good-faith effort to avoid privacy violations, data destruction, service degradation and interruption to others.
- Access, use and retain only the minimum data needed to demonstrate a vulnerability. Never exfiltrate, store or share another player’s data.
- Use your own player name and your own device for testing. Do not test against other players’ records.
- No denial-of-service or load testing, no spam, no social engineering of staff or customers, no physical attacks, no attacks on our suppliers.
- Do not disclose publicly or to third parties before we have remediated and coordinated disclosure with you.
- Stop and tell us immediately if you encounter personal or otherwise sensitive data.
- Comply with applicable law.
7. Confidentiality and data protection
Reports are treated as confidential. Personal data in a report is processed solely to handle the report and remediate the issue, on Art. 6(1)(f) GDPR — our legitimate interest in the security of our products — and Art. 6(1)(c) where a legal obligation applies. Reporter contact details are kept only as long as the disclosure process and record-keeping require. The privacy policy applies.
8. Recognition
We do not run a paid bug-bounty programme. With your consent we are glad to credit you in the release notes accompanying the fix, or in a public acknowledgement. You may also stay anonymous.
9. Security of the service
For transparency, and because the Cyber Resilience Act expects it to be stated rather than assumed:
- traffic is encrypted in transit with TLS; database and object storage are encrypted at rest;
- backend requests are authenticated with an application bearer token;
- administrative access uses multi-factor authentication and least privilege;
- database backups run daily;
- security and conformity updates are provided for at least five years from the date a version is placed on the market (§ 2.4 of the terms of service);
- vulnerabilities found here or reported by you are fixed in an app release through the App Store, and in a backend deployment for server-side issues — server-side fixes require nothing from you.
10. No warranty
This policy creates no contractual obligation, warranty or entitlement to reward, and waives no right of the Provider except as stated in § 5. We may update it; the current version is always at https://snapshots-quiz.app/security/ and is the address named in the Policy: field of our security.txt.
11. Contact
Security reports: security@digitalfreedom.co.za · https://security.digitalfreedom.co.za General: hello@digitalfreedom.co.za · Website: https://digitalfreedom.co.za
© 2025–2026 DigitalFreedom Global LLC. All rights reserved.