Information on security vulnerabilities

At Adevinta Real Estate, S.L.U. (hereinafter, "the Company"), the protection of our customers' data is extremely important to us. We greatly value the role security researchers play in helping to keep our systems and information secure. To encourage responsible vulnerability disclosure, the Company's security team is committed to working closely with the research community. We will carefully investigate all legitimate vulnerability reports, reproduce any confirmed issues, and work quickly to resolve them appropriately.

If you discover a potential security vulnerability in any of the Company's products or services, please inform us immediately. We will examine every credible report received and do our best to quickly resolve any validated vulnerabilities.

We ask that you do not publicly disclose your findings until we have had the opportunity to review and address the reported issues with you first. While we will consider reasonable requests for public disclosure, the Company reserves the right to deny them. Your help in maintaining the Company's security is greatly appreciated.

Responsible Disclosure Guidelines

To encourage responsible disclosure, the Company will not pursue legal action against security researchers who assess vulnerabilities, provided they comply with this policy, including:

  • Notify the Company and provide full details via the HackerOne Vulnerability Disclosure Program form below.
  • Only test accounts that you own or for which you have explicit permission
  • Do not access, modify, or delete data that does not belong to you
  • Do not interact with other users or employees; any actions must be performed within test accounts under your control.
  • Do not exploit vulnerabilities beyond what is necessary to identify and report them
  • Do not perform denial-of-service attacks, phishing, social engineering, or physical attacks
  • Do not perform any tests on the physical security of the Company's facilities, personnel, equipment, etc.
  • Do not test third-party services that integrate with the Company
  • Do not violate laws or disrupt services
  • By submitting a security vulnerability report, you grant the Company permission to use the information contained in your report as we deem appropriate.

Public Acknowledgement Policy

Currently, the Company DOES NOT publicly disclose or maintain a list of security vulnerabilities reported by external third parties or the individuals who reported them.

Privacy

For information on how the Company processes and protects personal data, please refer to our Privacy Policy available here.

Policy Changes

The Company reserves the right to terminate or modify this vulnerability disclosure program and policy at any time. Before conducting any security testing or taking action based on this policy, please review the latest version here.

Please fill out this form to report a vulnerability:

If the form does not load, you can access it directlyhere.