Reference document
Coordinated vulnerability disclosure
Version 2.0 — effective as of 01/04/2026
RDMC encourages responsible reporting of vulnerabilities affecting its public assets.
Channel
Reports may be sent to security@rdmc.fr.
Expected information
- affected asset or URL;
- description and impact;
- minimal reproduction steps;
- non-destructive evidence;
- reporter contact details.
Rules
- do not access more data than necessary;
- do not modify, delete, exfiltrate or publish data;
- do not perform denial of service, social engineering or physical intrusion;
- do not disrupt customers, users or providers;
- allow a reasonable remediation window before publication.
Handling
Where possible, RDMC acknowledges receipt, qualifies the report and coordinates remediation. No financial reward program is presumed.