ParcelDossier

Security Incident Reporting

Version: v1.0 | Effective: 2026-08-30

This page is public and can be reached and used without holding a subscription; it describes how to report a security incident or vulnerability affecting ParcelDossier, the property assessment service provided by Cheppers Zrt.

Scope

The following are security incidents for the purposes of this process:

The following are out of scope for this channel and are handled elsewhere:

How to report

Send your report to product@cheppers.com.

Cheppers acknowledges a report within 2 business days.

You do not need a subscription and you do not need an account to send a report. Reports from customers, from independent researchers, and from members of the public are all accepted through the same channel and are triaged the same way.

Include the following, as far as you have it:

A security.txt file is published at the well-known location for the Cheppers site and points at the same contact as this page, so that automated tooling and researchers find one address and not two: https://parceldossier.com/.well-known/security.txt.

What happens after you report

  1. Acknowledgement. Cheppers confirms receipt of your report within 2 business days and names a point of contact for it.
  2. Triage and severity assignment. Cheppers reproduces or corroborates the report where it can and assigns a severity based on what data or function is reachable and by whom.
  3. Containment. Where the issue is live and exploitable, Cheppers acts to stop further exposure before it works on a permanent fix, which may include disabling an affected path.
  4. Investigation. Cheppers reconstructs what happened using the per-tenant append-only audit log of security-relevant events (OBS-01), which is what establishes whether the issue was exercised and against which tenants.
  5. Credential rotation or invalidation. Where an API credential is implicated, the affected credential is rotated or invalidated (TEN-02) and the affected tenant is told that this has happened.
  6. Remediation. Cheppers develops, tests, and deploys the fix, and verifies that the reported behaviour no longer occurs.
  7. Closing summary. Cheppers sends you a written summary stating what was found, what was changed, and whether any customer notification was made.

Notification of affected customers

Cheppers notifies customers who may be affected by an incident that is relevant to them. Notification goes to the contact associated with the affected subscription.

Where the incident is a personal data breach, notification follows the Data Processing Addendum: without undue delay, and in any event within 48 hours of Cheppers becoming aware of the breach.

A notification states:

Where not all of this is known at once, Cheppers sends what it has and follows up as more emerges rather than delaying the first notification.

Good-faith research

Cheppers will not pursue legal action against a researcher who reports in good faith and who:

Cheppers does not currently operate a paid bug-bounty programme. No reward, bounty, or payment is offered or implied for a report made under this process.

What we do not claim

So that this page is not read as claiming more than it says:

The acknowledgement and notification commitments on this page are process commitments and are the only timing commitments made here.

Contact

Security incident reports and vulnerability reports: product@cheppers.com.