Responsible disclosure
If you found a security vulnerability in our systems, help us fix it before it becomes public.
How to report
Send details to [email protected] with the subject "Security report". Include, as far as possible: the affected system or URL, steps to reproduce the issue, potential impact, and any evidence (screenshots, logs) that helps confirm it. A working exploit is not required.
Scope
This program covers systems operated directly by RedScopeX: the public site redscopex.com, the application app.redscopex.com, and its associated API. It does not cover third-party infrastructure we use (for example, Cloudflare) — those reports should go to the relevant vendor.
What we ask
- Give us reasonable time to investigate and fix the issue before disclosing it publicly.
- Avoid accessing, modifying or deleting data that isn't yours beyond what's strictly necessary to demonstrate the issue.
- Don't run tests that could degrade service for other users (for example, denial-of-service attacks).
- Don't use social engineering against our staff or customers.
Our commitment (safe harbor)
If your research is conducted in good faith and within this scope, we will not pursue legal action against you for finding and responsibly reporting the vulnerability.
Response times
We acknowledge receipt of a report within a reasonable time frame and keep you informed of progress while we work on a fix. The exact timeline depends on the severity and complexity of the finding.
Out of scope
We don't consider the following valid reports: brute-force attacks with no underlying vulnerability, issues requiring physical access to a device, reports based solely on automated tooling without manual verification, or findings already known to our team.