Security

Vulnerability disclosure policy

If you have found a security issue in something we run, this page tells you where to send it and what to expect back.

Policy

Reporting

Send reports to hello@rynexor.com with "Security" in the subject line. Include enough detail to reproduce the issue: the affected URL or endpoint, the steps, and what you observed. A proof of concept is welcome; a scanner export on its own usually is not.

What we commit to

  • We acknowledge reports within 3 working days.
  • We give you an initial assessment within 10 working days.
  • We keep you updated while we work on it.
  • We will not pursue legal action against anyone who follows this policy in good faith.
  • We credit reporters publicly if they want it, and stay quiet if they do not.

Scope

This policy covers systems Rynexor operates: this website and the infrastructure behind it. It does not cover client systems. If you have found something in a client environment through work we did, contact us and we will route it. Do not test a client's systems on the strength of this policy.

Out of scope

  • Denial of service, volumetric testing, and anything that degrades availability.
  • Social engineering of our people or our suppliers.
  • Physical attacks against offices or hardware.
  • Reports generated entirely by an automated scanner with no demonstrated impact.
  • Missing headers or cookie flags with no exploitable consequence. Tell us anyway, but expect it to be triaged low.

What we ask

  • Give us reasonable time to fix the issue before publishing.
  • Do not access, modify or retain data that is not yours. If you reach client data, stop and tell us immediately.
  • Use only the minimum testing necessary to demonstrate the problem.

Rewards

We do not currently run a paid bounty programme. There is no payout for reports today. Credit, a written thank you, and a prompt fix are what we can offer. We state that upfront so you do not spend a weekend expecting a bounty that is not there.