Xenith values the security research community and welcomes good-faith reports of potential vulnerabilities. This document explains how to report an issue and what you can expect from us in return.
The always-current version of this policy is also published at xenith.life/responsible-disclosure. If the two ever disagree, the live page is canonical.
Email security@xenith.life with a clear description of the issue. Where possible, include:
- The type of vulnerability and the affected URL or component.
- Step-by-step instructions to reproduce, and any proof-of-concept.
- The potential impact, as you understand it.
We aim to acknowledge reports within 5 business days and to keep you informed as we investigate and remediate.
To keep research safe and lawful, please:
- Make a good-faith effort to avoid privacy violations, data destruction, and interruption or degradation of the Service.
- Only interact with accounts you own or have explicit permission to test. Do not access, modify, or delete other users' data.
- Avoid automated scanning that generates excessive traffic, and do not perform denial-of-service, social engineering, or physical attacks.
- Give us a reasonable amount of time to remediate before public disclosure, and do not disclose details publicly without our prior written consent.
If you make a good-faith effort to comply with this policy during your research, we will consider your actions authorized, will not pursue or support legal action against you, and will work with you to understand and resolve the issue quickly. If legal action is initiated by a third party against you for activity conducted under this policy, we will make this authorization known.
Reports limited to the following generally do not qualify: missing best-practice headers without a demonstrated exploit, reports from automated tools without validation, social engineering of our staff or users, and vulnerabilities in third-party services we do not control (please report those to the relevant provider).
Xenith does not currently operate a paid bug bounty program. We are grateful for responsible reports and are happy to publicly credit researchers who wish to be recognized.
For a summary of the technical and organizational measures we use, including encryption, infrastructure, access controls, and application security, see the full Security Policy on the live site.