Vulnerability disclosure
Tell us if something is broken. Do not exploit it.
We accept good-faith reports about Xpancom-operated systems. There is no public bug bounty. We will not pursue a reporter who follows this policy.
01 / Section
Scope.
In scope: xpancom.com, app.xpancom.com, auth.xpancom.com, tokenized intake, and the APIs those hosts expose. Out of scope: third-party products we did not write, social engineering of staff or clients, physical security, and denial-of-service testing that degrades service.
02 / Section
How to report.
- Email security@xpancom.com with steps to reproduce, the affected URL, and the impact.
- Use a test account you are invited to, or a finding that does not require an account.
- Do not access data that is not yours. Do not persist in a system after proving the issue.
- Give us a reasonable time to fix before public disclosure. Coordinated disclosure is the default.
- Do not demand payment. We may thank a reporter; we do not run a bounty program.
03 / Section
Safe harbor.
If you follow this policy, act in good faith, and do not violate the law in a way this policy cannot authorize, Xpancom will not bring a lawsuit against you for the report. This is not permission to attack systems outside the scope above.