Vulnerability Disclosure Policy (VDP)
Scope
This policy applies to public-facing assets under vtr3dprint.com.br and subdomains directly managed by VTR 3D Print.
How to report
Send reports to contato@vtr3dprint.com.br with subject line [VDP]. Include reproduction steps, impact and supporting evidence.
Expected good-faith testing
- Act in good faith and avoid service disruption.
- Do not access, alter or delete third-party data.
- Limit testing to what is strictly required to prove risk.
- Keep vulnerabilities confidential until remediation.
Out of scope
- Social engineering, phishing or physical attacks.
- Denial of Service (DoS/DDoS) or spam.
- Reports without a realistic exploitation path.
Recognition
Contributors may be acknowledged in our Hall of Fame, subject to permission.
Last reviewed on February 21, 2026.