Tvarka ATK API · Vulnerability Disclosure

Tvarka Atk Api Vulnerability Disclosure

Vulnerability disclosure

Tvarka ATK API runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

AuthenticationDigital SignatureeIDASQESLithuaniaOpenAPIeIDSmart-IDMobile-IDNFCTimestampingLTVWebhooksIdentityTrust ServicesGDPR
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
https://tvarka.pro/kontaktai/
Contact
info@tvarka.pro

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-09'
method: searched
probe: true
source: https://tvarka.pro/saugumas/
policy:
  - https://tvarka.pro/saugumas/
contact:
  - https://tvarka.pro/kontaktai/
  - info@tvarka.pro
security_txt: false
bug_bounty: false
program:
  kind: informal-invitation
  statement_lt: >-
    "Pastebejote spraga? Jei radote saugumo problema ar turite klausimu apie duomenu apsauga,
    susisiekite - i saugumo pranesimus reaguojame pirmiausia."
  statement_en: >-
    "Spotted a vulnerability? If you found a security problem or have questions about data
    protection, get in touch - we respond to security reports first."
  note: >-
    A published, explicit invitation to report vulnerabilities on the provider's security page, with
    a stated response priority. There is no dedicated security@ mailbox, no /.well-known/security.txt
    (404 on atk.tvarka.pro, tvarka.pro and sign.tvarka.pro), no named SLA and no bug-bounty program
    (no HackerOne / Bugcrowd / Intigriti presence found). Reports route through the general contact
    page.
gaps:
  - No RFC 9116 security.txt on any host.
  - No dedicated security contact address; reports go to the general info@ mailbox.
  - No published disclosure timeline or safe-harbour statement.
evidence:
  - {source: 'https://tvarka.pro/saugumas/', http_status: 200, kind: security-page, keywords: [saugumo problema, saugumo pranesimus, BDAR, eIDAS, QTSP, TLS]}
  - {source: 'https://tvarka.pro/kontaktai/', http_status: 200, kind: contact-page}
  - {source: 'https://atk.tvarka.pro/.well-known/security.txt', http_status: 404, kind: security.txt}
  - {source: 'https://tvarka.pro/.well-known/security.txt', http_status: 404, kind: security.txt}
  - {source: 'https://sign.tvarka.pro/.well-known/security.txt', http_status: 404, kind: security.txt}