Skip to main content
Techx4u, Inc

Security

Responsible disclosure policy

We are a security company, so we hold ourselves to the standard we ask of clients. If you have found a vulnerability in our systems, we want to hear about it and we will treat you well for telling us.

How to report

Email security@techx4u.com with a clear description of the issue. Please include enough detail for us to reproduce it — affected URL or endpoint, steps taken, and what you observed. Proof-of-concept code and screenshots are welcome.

If you would like to encrypt your report, request our PGP key in a first message and we will provide it before you send details.

Our commitment to you

  • We acknowledge every report within 3 working days
  • We provide an initial assessment within 10 working days
  • We keep you updated until the issue is resolved
  • We credit you publicly if you would like us to
  • We will not pursue legal action for good-faith research within this policy

Scope

This policy covers internet-facing systems operated by Techx4u, Inc on the techx4u.com domain and its subdomains. Systems operated by our clients are explicitly out of scope — please do not test them, even if you believe we manage them.

Testing rules

Safe harbour applies only to research conducted within these limits:

  • Do not access, modify or delete data belonging to anyone else
  • Do not run denial-of-service or volumetric testing
  • Do not use automated scanners that generate high request volumes
  • Do not social-engineer our staff, clients or suppliers
  • Do not test physical security
  • Stop as soon as you have demonstrated the issue exists
  • Give us reasonable time to remediate before any public disclosure

Out of scope

The following are generally not accepted as vulnerabilities: missing security headers with no demonstrated impact, reports generated solely by an automated scanner without validation, self-XSS, clickjacking on pages with no sensitive action, email configuration issues with no exploit path, and vulnerabilities requiring an already-compromised device.

Rewards

We do not currently operate a paid bug bounty. We do offer public credit, a written acknowledgement you can reference, and our genuine thanks. Reports of high or critical severity may be rewarded at our discretion.