Security at Julditec
Security officer
Miguel Ángel Júlvez Ibáñez, CEO and information security officer.
Contact: security@julditec.com
Our commitment
Julditec develops and maintains portals and intranets built on Liferay DXP for public bodies and private companies. We apply the measures of Spain's National Security Framework (Esquema Nacional de Seguridad, ENS, Royal Decree 311/2022) to the systems we develop and maintain for the public sector.
What we do in security
- Secure code review in every delivery.
- Vulnerability analysis and patch validation on the portals we maintain.
- Dependency management and Liferay security updates.
- Periodic configuration review: TLS, headers and access control.
Testing on client systems
We only analyse client systems with prior written authorisation. That authorisation sets the scope, the dates and the people responsible. We report findings to the system owner and never publish them without their consent.
How to report a vulnerability
If you find a vulnerability in our systems or in software we have developed, email us at security@julditec.com with the subject “Vulnerability”. Include a description, the steps to reproduce it and the impact you estimate. We commit to:
- acknowledge receipt within 3 working days at most;
- keep you informed while we fix it;
- take no legal action against anyone who reports in good faith and without causing harm.