[ Security ]
Found something in our perimeter?
Effective 28 July 2026. We spend our days reporting other people's bugs, so we know exactly how it feels to send a good report into silence. Here is what you get from us.
Reporting
Email security@rootxlabs.ai. One report per issue. If you need encryption, ask in the first message and we will send you a key before you send details.
A report we can act on has:
- the affected asset, and the exact request or input that triggers it;
- reproduction steps that a triager can re-run cold, in order;
- what an attacker actually gains — the impact, not the CVSS vector;
- any account, token or precondition your proof-of-concept relies on.
Scanner output pasted verbatim, a screenshot of a tool's severity rating, or a class of issue described without a working case is not a report. We will close it, and say why.
What we commit to
| Acknowledgement | Within 2 business days, from a human. |
|---|---|
| Triage decision | Within 7 days — valid, duplicate, or rejected with reasoning. |
| Fix target | 30 days for critical and high, 90 days otherwise. |
| Credit | Named in the advisory, unless you would rather not be. |
If we miss one of these dates, you will hear the reason from us rather than have to chase it. If we disagree that an issue is real, we will tell you what specifically we could not reproduce, so you can correct us.
Safe harbour
Research conducted in good faith under this policy is authorized. We will not pursue legal action, and if a third party does so over research that stayed within this policy, we will make clear that it was authorized.
Good faith means:
- you stop at proof — no pivoting further into our infrastructure once access is demonstrated;
- you take the minimum data needed to prove impact, do not read other people's data beyond that, and delete what you took;
- no denial of service, no automated load that degrades the service for anyone else, no social engineering of our staff or customers, no physical intrusion;
- you give us a reasonable chance to fix it before you publish;
- you do not use the access to harm us or a customer, or hold a finding for leverage.
Scope
Any asset we operate is in scope, including this site and the platform. Notably out of scope, because reporting them helps no one:
- missing hardening headers with no demonstrated exploit;
- reports whose only evidence is a rating from an automated scanner;
- self-XSS, clickjacking on a page with no state-changing action, and missing SPF or DMARC on a domain that sends no mail;
- findings in third-party services we merely consume — report those to the vendor, though we would like to know;
- an
Access-Control-Allow-Originreflection without credentials attached.
Rewards
We do not run a paid bounty programme yet, and we would rather say that plainly than imply one. Valid reports get public credit, a written advisory once fixed, and swag if you want it. When a paid programme exists it will be announced here first, and everyone who reported before then will be told.
How we disclose to other vendors
The same standard applies when we are the reporter. Findings we produce against third-party products go to the vendor privately, with a working reproduction, and we hold publication for 90 days from the report or until a fix ships, whichever comes first. We extend that when a vendor is engaged and making progress. We publish sooner only if the issue is already being exploited.
Where a finding came out of a customer engagement, we coordinate timing with that customer first and never name them without permission. We do not name an affected product publicly until its vendor has shipped a fix, which is why several of our findings are not listed anywhere on this site.
security.txt
Machine-readable contact details are at https://rootxlabs.ai/.well-known/security.txt.