Security Vulnerability Disclosure Policy
At eDrixx, we take the security of our systems and users seriously. We welcome responsible reports from security researchers who discover potential vulnerabilities.
Reporting a Vulnerability
If you believe you have found a security vulnerability affecting services provided by eDrixx, please report it to us privately at security@edrixx.com.
Please include:
- A description of the vulnerability
- The affected URL, service, or component
- Steps to reproduce the issue
- Any relevant screenshots, logs, or proof-of-concept information
Please do not include unnecessary personal data in your report.
Responsible Research
We ask that you:
- Avoid accessing, modifying, deleting, or downloading data that does not belong to you
- Do not disrupt our services, including through denial-of-service testing
- Do not use social engineering, phishing, spam, or physical attacks
- Do not publicly disclose the vulnerability before we have had a reasonable opportunity to investigate and address it
- Stop testing and contact us if you encounter sensitive or personal information
Our Commitment
If you act in good faith and follow this policy, we will make reasonable efforts to:
- Acknowledge your report
- Investigate the issue
- Keep you informed of significant progress
- Address valid security vulnerabilities as appropriate
We will not pursue legal action against researchers for good-faith security research conducted in accordance with this policy.
This policy does not create any entitlement to payment or a bug bounty unless explicitly agreed in advance.