Security
Vulnerability disclosure policy
If you have found a security issue in something we run, this page tells you where to send it and what to expect back.
Policy
Reporting
Send reports to hello@rynexor.com with "Security" in the subject line. Include enough detail to reproduce the issue: the affected URL or endpoint, the steps, and what you observed. A proof of concept is welcome; a scanner export on its own usually is not.
What we commit to
- We acknowledge reports within 3 working days.
- We give you an initial assessment within 10 working days.
- We keep you updated while we work on it.
- We will not pursue legal action against anyone who follows this policy in good faith.
- We credit reporters publicly if they want it, and stay quiet if they do not.
Scope
This policy covers systems Rynexor operates: this website and the infrastructure behind it. It does not cover client systems. If you have found something in a client environment through work we did, contact us and we will route it. Do not test a client's systems on the strength of this policy.
Out of scope
- Denial of service, volumetric testing, and anything that degrades availability.
- Social engineering of our people or our suppliers.
- Physical attacks against offices or hardware.
- Reports generated entirely by an automated scanner with no demonstrated impact.
- Missing headers or cookie flags with no exploitable consequence. Tell us anyway, but expect it to be triaged low.
What we ask
- Give us reasonable time to fix the issue before publishing.
- Do not access, modify or retain data that is not yours. If you reach client data, stop and tell us immediately.
- Use only the minimum testing necessary to demonstrate the problem.
Rewards
We do not currently run a paid bounty programme. There is no payout for reports today. Credit, a written thank you, and a prompt fix are what we can offer. We state that upfront so you do not spend a weekend expecting a bounty that is not there.