Security
Responsible disclosure policy
We are a security company, so we hold ourselves to the standard we ask of clients. If you have found a vulnerability in our systems, we want to hear about it and we will treat you well for telling us.
How to report
Email security@techx4u.com with a clear description of the issue. Please include enough detail for us to reproduce it — affected URL or endpoint, steps taken, and what you observed. Proof-of-concept code and screenshots are welcome.
If you would like to encrypt your report, request our PGP key in a first message and we will provide it before you send details.
Our commitment to you
- We acknowledge every report within 3 working days
- We provide an initial assessment within 10 working days
- We keep you updated until the issue is resolved
- We credit you publicly if you would like us to
- We will not pursue legal action for good-faith research within this policy
Scope
This policy covers internet-facing systems operated by Techx4u, Inc on the techx4u.com domain and its subdomains. Systems operated by our clients are explicitly out of scope — please do not test them, even if you believe we manage them.
Testing rules
Safe harbour applies only to research conducted within these limits:
- Do not access, modify or delete data belonging to anyone else
- Do not run denial-of-service or volumetric testing
- Do not use automated scanners that generate high request volumes
- Do not social-engineer our staff, clients or suppliers
- Do not test physical security
- Stop as soon as you have demonstrated the issue exists
- Give us reasonable time to remediate before any public disclosure
Out of scope
The following are generally not accepted as vulnerabilities: missing security headers with no demonstrated impact, reports generated solely by an automated scanner without validation, self-XSS, clickjacking on pages with no sensitive action, email configuration issues with no exploit path, and vulnerabilities requiring an already-compromised device.
Rewards
We do not currently operate a paid bug bounty. We do offer public credit, a written acknowledgement you can reference, and our genuine thanks. Reports of high or critical severity may be rewarded at our discretion.
