Security

Responsible disclosure

If you found a security vulnerability in our systems, help us fix it before it becomes public.

How to report

Send details to [email protected] with the subject "Security report". Include, as far as possible: the affected system or URL, steps to reproduce the issue, potential impact, and any evidence (screenshots, logs) that helps confirm it. A working exploit is not required.

Scope

This program covers systems operated directly by RedScopeX: the public site redscopex.com, the application app.redscopex.com, and its associated API. It does not cover third-party infrastructure we use (for example, Cloudflare) — those reports should go to the relevant vendor.

What we ask

Our commitment (safe harbor)

If your research is conducted in good faith and within this scope, we will not pursue legal action against you for finding and responsibly reporting the vulnerability.

Response times

We acknowledge receipt of a report within a reasonable time frame and keep you informed of progress while we work on a fix. The exact timeline depends on the severity and complexity of the finding.

Out of scope

We don't consider the following valid reports: brute-force attacks with no underlying vulnerability, issues requiring physical access to a device, reports based solely on automated tooling without manual verification, or findings already known to our team.