Security
Updated 2026-09-19
- Legal name
- Babete
- Registered address
- Travessa da Boa Hora, Lisboa, Portugal
- Contact
- security@babete.pt
- Governing law
- Portugal — Lisboa
- Supervisory authority
- CNPD — Comissão Nacional de Proteção de Dados
Scope
This page covers how to report a security issue in Sinal — the website, the application, and the read API.
How to report
Write to the address above with what you found, the steps to reproduce it, and its likely impact. Encrypt anything sensitive if you can; otherwise send it in plain text and we will ask for more detail over the same channel.
What to expect
Once you report, here is the timeline you can expect.
- Acknowledgement within 5 business days.
- A fix or an explanation within 90 days.
Safe harbour
Babete will not pursue legal action against a good-faith report that stays within the scope and rules on this page, does not access or exfiltrate more data than needed to demonstrate the issue, and is reported to us before any public disclosure.
Out of scope
The following are not in scope for this policy.
- Testing our own rate limits by sending high volumes of traffic.
- Denial-of-service testing.
- Social engineering of Babete or its contacts.
- Vulnerabilities in third-party platforms Sinal links to, such as the procurement portals themselves.
No bounty
Babete does not run a paid bug bounty programme. A well-documented report earns our thanks and, if you want it, a credit.
Regulatory note
Babete is a microenterprise. The Cyber Resilience Act does not apply to a standalone SaaS product, and NIS2 excludes micro and small enterprises outside its named sectors — neither obligation formally applies to Sinal. This page and security.txt are published voluntarily, in the same spirit as the accessibility statement.