Responsible disclosure. Export discipline.
We publish this page so researchers know how to reach us, and so customers, partners, and allied governments know where we stand on security and export compliance.
[ EN ] النسخة المعتمدة بالإنجليزية. الترجمة للراحة فقط.
01 · RESPONSIBLE DISCLOSURE
How to report a vulnerability
If you believe you have found a vulnerability in post77.com, in Aethon firmware, in the P77 Aegis stack, or in any related infrastructure, tell us. We welcome it. Send a plain-text email to security@post77.com describing the issue and steps to reproduce. We will acknowledge within 72 hours and keep you informed until resolution.
IN SCOPE
- ✓ post77.com and subdomains
- ✓ Aethon firmware (under signed test licence)
- ✓ P77 Aegis reference binaries
OUT OF SCOPE
- × Third-party sites linked from post77.com
- × Denial-of-service via volumetric flooding
- × Social engineering of Post77 staff
We will not pursue legal action against researchers acting in good faith under this policy.
02 · EXPORT COMPLIANCE
Export compliance posture
Aethon and P77 Aegis are classified as dual-use and, depending on configuration, subject to EU Regulation 2021/821 and allied ITAR controls. We do not transfer, deliver, or grant access to controlled items, software, or technical data without the correct licence and qualified end-user.
All buyer applications are routed through an end-user certification and compliance review that typically takes 6–10 weeks. Qualified allocation goes to NATO and coalition allies first. Multi-year contract buyers are prioritised in every batch — the paperwork is ready to accelerate qualification.
03 · DATA SECURITY
How we protect site and submission data
post77.com is served over TLS (HTTPS-only). Form submissions are transmitted over TLS and dispatched through Resend (EU-aligned). Internal access to submission records is restricted to the Post77 operations team.
We run Plausible for analytics — cookieless, no PII, no third-party sharing. The only cookie set by this site is a first-party 'locale' preference (SameSite=Lax, 365-day max).
CONTACT
- Security: security@post77.com
- Partnerships / legal: partnerships@post77.com
LEGAL ENTITY
Post77, S.A.
NIPC 519065506 · Share capital € 50,000.00
Estrada Nacional 254, km 45, Monte da Galvoeira
7005-210 Évora · Portugal
Last updated: 2026-04-21