RESPONSIBLE DISCLOSURE
How to report a security vulnerability to us responsibly, and what you can expect in return.
ON THIS PAGE
1 Our Commitment
Johmarg Strips takes the security of our website and our customers' information seriously. We value the work of security researchers and members of the public who help us identify and resolve vulnerabilities. This Responsible Disclosure Policy sets out how to report a security concern to us, and the process we follow once a report is received.
2 Scope
This policy applies to security vulnerabilities discovered on:
- Our official website, johmargstrips.co.za, and any subdomains we operate;
- Forms, quote requests and contact functionality hosted on our website; and
- Any other digital service that we publicly identify as being in scope.
This policy does not apply to third-party services we link to but do not control (for example, social media platforms), or to physical products, showrooms or premises.
3 How to Report a Vulnerability
If you believe you have discovered a security vulnerability affecting our website, please report it to us as soon as possible by emailing:
Email: johmargstrips@outlook.com with the subject line "Security Vulnerability Report"
Please do not disclose the issue publicly, on social media, or to any third party until we have had a reasonable opportunity to investigate and address it.
4 What to Include in Your Report
To help us investigate and resolve the issue quickly, please include as much of the following as possible:
- A clear description of the vulnerability and its potential impact;
- Steps to reproduce the issue, including URLs, screenshots or a proof-of-concept where relevant;
- The type of vulnerability (for example, cross-site scripting, information disclosure, misconfiguration); and
- Your contact details, so we can follow up with questions or updates.
5 Our Response Process
- Acknowledgement — we aim to acknowledge receipt of your report within 3 business days.
- Assessment — our team will investigate and assess the validity and severity of the reported issue.
- Resolution — where a vulnerability is confirmed, we will work to remediate it within a reasonable timeframe based on its severity.
- Follow-up — we will keep you informed of our progress and let you know once the issue has been resolved.
6 Guidelines for Researchers
When testing for vulnerabilities, please:
- Avoid accessing, modifying or deleting data that does not belong to you;
- Avoid actions that could degrade the performance or availability of our website (such as denial-of-service testing);
- Avoid social engineering, phishing, or physical attacks against our staff, customers or premises; and
- Only interact with accounts or data you own, or with explicit permission.
7 Out of Scope
The following are generally considered out of scope for reports under this policy: missing security headers without a demonstrated exploit, clickjacking on pages with no sensitive actions, reports generated purely by automated scanners without manual verification, and issues affecting outdated or unsupported browsers.
8 Safe Harbour
We will not pursue legal action against researchers who discover and report vulnerabilities in good faith, in accordance with this policy, and who do not cause harm to our systems, data, or customers in the process. This safe harbour applies only to activity that stays within the guidelines set out above.
9 Contact Us
To report a vulnerability or ask a question about this policy, please reach out to our team.
JOHMARG STRIPS — SECURITY REPORTS
Email: johmargstrips@outlook.com | Phone: +27 83 324 0532
CONTACT US