Responsible Disclosure Policy
Last updated:
We are a security company, and we take the security of our own systems seriously. If you believe you have found a vulnerability in a system we own or operate, we want to hear from you and will work with you to fix it.
Scope
In scope:
- securegenix.com and its subdomains operated by Securegenix
Out of scope:
- Systems belonging to our clients. If you find an issue affecting one of our clients, please report it directly to that organisation.
- Third-party services we use, such as our hosting or email providers. Please report those to the provider.
- Denial-of-service testing, spam, social engineering or phishing of our staff, and physical attacks on our offices.
- Findings from automated scanners without a demonstrated security impact, such as missing headers on non-sensitive pages, banner disclosure or self-XSS.
How to report
Email security@securegenix.com with:
- a description of the vulnerability and its potential impact;
- the affected URL, component or system;
- clear steps to reproduce, including any proof-of-concept code or screenshots; and
- how you would like to be credited, if at all.
[Placeholder: If you publish a PGP key for encrypted reports, add its fingerprint and a link here, and add an Encryption field to security.txt.]
Our machine-readable contact details are in /.well-known/security.txt.
Rules of engagement
When researching vulnerabilities, please:
- only test against accounts and data you own or have explicit permission to use;
- access, modify or delete only the minimum data needed to demonstrate the issue, and stop as soon as you confirm it;
- not degrade or disrupt our services or other users;
- not use the vulnerability for any purpose other than reporting it to us; and
- give us reasonable time to fix the issue before disclosing it publicly. We ask for 90 days by default and are happy to agree a different timeline.
What you can expect from us
- We will acknowledge your report within [Placeholder: e.g. 3] business days.
- We will confirm whether we can reproduce the issue and keep you informed of our progress.
- We will let you know when the issue is fixed and agree a disclosure date with you.
- With your permission, we will credit you publicly for the discovery.
Safe harbour
If you act in good faith and follow this policy, we will consider your research authorised, we will not pursue or support legal action against you, and we will work with you to understand and resolve the issue quickly. If a third party brings legal action against you for activity that complied with this policy, we will make it known that your actions were authorised by us.
Rewards
We do not currently run a paid bug bounty programme.