Security

Updated 2026-09-19

Legal name
Babete
Registered address
Travessa da Boa Hora, Lisboa, Portugal
Contact
security@babete.pt
Governing law
Portugal — Lisboa
Supervisory authority
CNPD — Comissão Nacional de Proteção de Dados

Scope

This page covers how to report a security issue in Sinal — the website, the application, and the read API.

How to report

Write to the address above with what you found, the steps to reproduce it, and its likely impact. Encrypt anything sensitive if you can; otherwise send it in plain text and we will ask for more detail over the same channel.

What to expect

Once you report, here is the timeline you can expect.

  • Acknowledgement within 5 business days.
  • A fix or an explanation within 90 days.

Safe harbour

Babete will not pursue legal action against a good-faith report that stays within the scope and rules on this page, does not access or exfiltrate more data than needed to demonstrate the issue, and is reported to us before any public disclosure.

Out of scope

The following are not in scope for this policy.

  • Testing our own rate limits by sending high volumes of traffic.
  • Denial-of-service testing.
  • Social engineering of Babete or its contacts.
  • Vulnerabilities in third-party platforms Sinal links to, such as the procurement portals themselves.

No bounty

Babete does not run a paid bug bounty programme. A well-documented report earns our thanks and, if you want it, a credit.

Regulatory note

Babete is a microenterprise. The Cyber Resilience Act does not apply to a standalone SaaS product, and NIS2 excludes micro and small enterprises outside its named sectors — neither obligation formally applies to Sinal. This page and security.txt are published voluntarily, in the same spirit as the accessibility statement.