Security Incident Reporting
Version: v1.0 | Effective: 2026-08-30
This page is public and can be reached and used without holding a
subscription; it describes how to report a security incident or
vulnerability affecting ParcelDossier, the property assessment service
provided by Cheppers Zrt.
Scope
The following are security incidents for the purposes of this
process:
- unauthorised access to a tenant’s Assessment Contexts, submitted
property data, generated assessments, or evidence records;
- exposure or leakage of an API credential, whether through the
Service, a log, or any Cheppers-controlled channel;
- a defect in authentication or authorisation that allows access
without a valid credential or beyond the scope of a valid
credential;
- a defect in tenant isolation that allows one tenant’s request to
read, infer, or affect another tenant’s data;
- a vulnerability in the public
/v1 API, including its
request handling, its job and result routes, and its rate limiting;
and
- a suspected personal data breach affecting data processed in
connection with the Service.
The following are out of scope for this channel and are handled
elsewhere:
- assessment output you disagree with, or a coverage or confidence
value you consider wrong - this is a support matter, not a security
matter;
- billing and metering disputes - see the Refund Policy;
- vulnerabilities in AWS services themselves - report these to AWS,
not to Cheppers.
How to report
Send your report to product@cheppers.com.
Cheppers acknowledges a report within 2 business days.
You do not need a subscription and you do not need an account to send
a report. Reports from customers, from independent researchers, and from
members of the public are all accepted through the same channel and are
triaged the same way.
Include the following, as far as you have it:
- a description of the issue and why you believe it is a security
issue;
- reproduction steps, or the evidence you observed if the issue is not
reproducible on demand;
- the time window in which you observed it, with the time zone;
and
- any affected tenant, assessment, or job identifiers.
A security.txt file is published at the well-known
location for the Cheppers site and points at the same contact as this
page, so that automated tooling and researchers find one address and not
two: https://parceldossier.com/.well-known/security.txt.
What happens after you
report
- Acknowledgement. Cheppers confirms receipt of your report within 2
business days and names a point of contact for it.
- Triage and severity assignment. Cheppers reproduces or corroborates
the report where it can and assigns a severity based on what data or
function is reachable and by whom.
- Containment. Where the issue is live and exploitable, Cheppers acts
to stop further exposure before it works on a permanent fix, which may
include disabling an affected path.
- Investigation. Cheppers reconstructs what happened using the
per-tenant append-only audit log of security-relevant events (OBS-01),
which is what establishes whether the issue was exercised and against
which tenants.
- Credential rotation or invalidation. Where an API credential is
implicated, the affected credential is rotated or invalidated (TEN-02)
and the affected tenant is told that this has happened.
- Remediation. Cheppers develops, tests, and deploys the fix, and
verifies that the reported behaviour no longer occurs.
- Closing summary. Cheppers sends you a written summary stating what
was found, what was changed, and whether any customer notification was
made.
Notification of affected
customers
Cheppers notifies customers who may be affected by an incident that
is relevant to them. Notification goes to the contact associated with
the affected subscription.
Where the incident is a personal data breach, notification follows
the Data Processing Addendum: without undue delay, and in any event
within 48 hours of Cheppers becoming aware of the breach.
A notification states:
- the nature of the incident;
- the categories of data affected, so far as they are known at the
time;
- the measures taken or proposed to address the incident and to limit
its effects; and
- a contact point for questions and for further information.
Where not all of this is known at once, Cheppers sends what it has
and follows up as more emerges rather than delaying the first
notification.
Good-faith research
Cheppers will not pursue legal action against a researcher who
reports in good faith and who:
- avoids privacy violations, and does not retain, sell, or disclose
data encountered while researching;
- avoids degrading the Service, including avoiding denial-of-service
testing, automated high-volume scanning, and spam;
- does not access or modify another tenant’s data beyond the minimum
needed to demonstrate the issue, and stops as soon as the issue is
demonstrated; and
- gives Cheppers a reasonable period to remediate before disclosing
the issue publicly.
Cheppers does not currently operate a paid bug-bounty programme. No
reward, bounty, or payment is offered or implied for a report made under
this process.
What we do not claim
So that this page is not read as claiming more than it says:
- Cheppers claims no certification under SOC 2, ISO 27001, or any
equivalent scheme for ParcelDossier.
- Cheppers does not promise a penetration-testing cadence for
ParcelDossier.
- Cheppers does not promise an uptime or availability service level
for ParcelDossier.
The acknowledgement and notification commitments on this page are
process commitments and are the only timing commitments made here.
Security incident reports and vulnerability reports:
product@cheppers.com.