Found something? We want to hear it.
Coordinated disclosure, with the scope and protections stated up front rather than left for you to guess at.
Safe harbour, plainly stated. If you act in good faith under this policy we will not pursue legal action against you, and will not contact your employer. We acknowledge every report within two business days, keep you updated, and credit you unless you would rather we did not.
01 How to report
Email security@xoopie.com. For anything time-critical, telephone the number above and say "security report" — you will be routed to a duty engineer rather than a queue.
A useful report contains what the issue is and where; steps to reproduce it; what an attacker could actually achieve (impact beats severity scores); any proof-of-concept; and how you would like to be credited, or that you would prefer not to be.
Please do not report through social media, a public issue tracker or a general enquiry form. Those are read during business hours by people who are not security engineers, which delays exactly the reports that should move fastest.
02 What we commit to
| Stage | Our commitment |
|---|---|
| Acknowledgement | Within 2 business days, from a person, not an autoresponder |
| Triage | Within 5 business days — validated, severity assigned, and you are told which |
| Updates | At least every 10 business days until closed |
| Fix target | Critical 7 days · High 30 days · Medium 90 days · Low best effort |
| Credit | Named in our acknowledgements once fixed, if you want it |
| Disclosure | Coordinated with you; 90 days is our default ceiling |
If we disagree with your assessment we will explain why rather than close the ticket silently. If we are slow, say so — that is legitimate feedback.
03 Scope
In scope
xoopie.comand its subdomains- Our client-facing platform and reporting interfaces
- Any software or tool we publish
- Our email and DNS configuration — SPF, DKIM, DMARC, takeover risks
Out of scope
- Denial of service or resource-exhaustion testing
- Social engineering of our staff, contractors or clients. Phishing us is not research
- Physical attacks, or anything targeting a data centre operator
- Automated scanner output with no demonstrated impact
- Missing hardening headers with no exploitable consequence
- Our clients' systems — these are not ours to authorise testing against
04 Rules of engagement
- Do not access, modify or exfiltrate data that is not yours. If you find a path to client data, stop and tell us the path — that finding is worth more to us than a proof of concept, and we will treat it accordingly.
- Do not degrade service. Test at a rate nobody but us would notice.
- Use your own test accounts where authentication is involved.
- Talk to us before publishing. One report per issue, related findings grouped.
05 Safe harbour
If you make a good-faith effort to comply with this policy, we will consider it authorised access under applicable computer-misuse law and not initiate or support legal action against you; we will not report you to your employer, university or a professional body; and we will work with you if a third party pursues action arising from research conducted under this policy.
This protection is not available where research is used to extort, where data is exfiltrated or sold, or where a client's systems are targeted without that client's own authorisation.
06 Reward
We do not operate a paid bug bounty. We are a young company and would rather promise nothing than promise a payment we cannot reliably make. What we do offer is a prompt technical response from the people who can fix the issue, public credit if you want it, and a written explanation of what we changed. Where a report is exceptional we will discuss a reward at the time.
07 Why this page exists
A security company without a disclosure policy is asking researchers to guess where to send a report — and in practice they do not guess, they move on. That means the finding sits unreported until somebody less friendly discovers it. We ask clients hard questions about how they would learn they had a problem; it would be inconsistent not to answer that question ourselves.