Política de divulgación responsable – AllDefense
En AllDefense creemos que la seguridad de la información es un compromiso compartido entre la organización, nuestros clientes y la comunidad de investigadores. Por ello, promovemos una política de divulgación responsable de vulnerabilidades, que busca garantizar la protección de los datos y la transparencia en la gestión de hallazgos de seguridad.
1. Alcance
Esta política aplica a todas las plataformas, servicios, sitios web y sistemas bajo el dominio alldefense.cl. No incluye sistemas de terceros que dependan de sus propias políticas de seguridad o infraestructura.
2. Cómo reportar una vulnerabilidad
-
Envía un correo a [email protected] o utiliza el formulario de contacto en https://alldefense.cl/contacto.
-
Describe de forma clara el hallazgo: URL afectada, pasos para reproducirlo, tipo de vulnerabilidad, impacto estimado, fecha en que se encontró.
-
Puedes adjuntar pruebas o capturas de pantalla que faciliten la comprensión del problema.
-
Si deseas permanecer en el anonimato, indícalo en tu mensaje; respetaremos tu decisión.
3. Buenas prácticas del reporte
-
No realices pruebas que puedan afectar la disponibilidad, integridad o confidencialidad de nuestros servicios, como ataques de denegación de servicio o explotación masiva.
-
Evita acceder a datos de terceros o alterar información que no te pertenece.
-
No publiques ni compartas detalles de la vulnerabilidad antes de que AllDefense tenga la oportunidad de analizar y corregir el problema.
-
Comprométete a realizar tus investigaciones de forma ética y con el menor impacto posible.
4. Compromiso de AllDefense
-
Analizaremos cada reporte recibido en un plazo máximo de 5 días hábiles y mantendremos una comunicación abierta durante el proceso de validación.
-
Reconoceremos públicamente (si así lo deseas) los hallazgos verificados en nuestra sección de agradecimientos.
-
No emprenderemos acciones legales contra investigadores que actúen de manera responsable y ética, siguiendo esta política de divulgación responsable.
-
Nos comprometemos a corregir las vulnerabilidades confirmadas en un tiempo razonable y comunicar a los usuarios los riesgos y las medidas adoptadas.
5. Agradecimientos
Valoramos el trabajo y la colaboración de la comunidad de seguridad. Agradecemos a todas las personas e investigadores que contribuyen a fortalecer la protección de AllDefense y de nuestros clientes mediante la detección responsable de vulnerabilidades.

Responsible Disclosure Policy – AllDefense
At AllDefense, we believe that information security is a shared commitment between the organization, our clients and the research community. Therefore, we promote a responsible vulnerability disclosure policy that aims to ensure data protection and transparency in the management of security findings.
1. Scope
This policy applies to all platforms, services, websites and systems under the alldefense.cl domain. It does not include third‑party systems that depend on their own security policies or infrastructure.
2. How to report a vulnerability
-
Send an email to [email protected] or use the contact form at https://alldefense.cl/contacto.
-
Clearly describe your finding: affected URL, steps to reproduce it, type of vulnerability, estimated impact and date found.
-
You may attach proof or screenshots to help us understand the issue.
-
If you wish to remain anonymous, please state that in your message; we will respect your choice.
3. Reporting best practices
-
Do not conduct tests that may affect the availability, integrity or confidentiality of our services, such as denial‑of‑service attacks or large‑scale exploitation.
-
Avoid accessing third‑party data or altering information that does not belong to you.
-
Do not publish or share details of the vulnerability before AllDefense has had the opportunity to analyze and fix the issue.
-
Commit to carry out your research ethically and with the least possible impact.
4. AllDefense’s commitment
-
We will analyze every report within a maximum of 5 business days and maintain open communication throughout the validation process.
-
We will publicly acknowledge verified findings (if you wish) in our acknowledgments section.
-
We will not take legal action against researchers who act responsibly and ethically, following this disclosure policy.
-
We commit to fixing confirmed vulnerabilities in a reasonable timeframe and informing users of the risks and measures adopted.
5. Acknowledgments
We value the work and collaboration of the security community. We thank all individuals and researchers who help strengthen the protection of AllDefense and our clients by responsibly discovering vulnerabilities.