Responsible Disclosure Policy
We believe vulnerabilities should be handled carefully and ethically. This policy covers how we disclose issues we find, and how you can report issues to us.
Last updated: 17 July 2026
1. Our commitment to clients
When we identify a vulnerability during an authorised engagement, we disclose it privately and directly to you. We provide clear details, evidence and remediation advice, and we give you the time and support to fix issues before they could be exploited. We never publish or share your vulnerabilities without your explicit consent.
2. Coordinated disclosure of third-party issues
If, in the course of our work, we discover a vulnerability in third-party software or services, we follow coordinated disclosure principles: we report the issue privately to the affected vendor, allow reasonable time for a fix, and avoid public disclosure that could put users at risk.
3. Reporting a vulnerability to Syntrix
If you believe you have found a security vulnerability affecting Syntrix or this website, we want to hear from you. Please email syntrixkal@gmail.com with:
- a clear description of the issue and its potential impact;
- the steps required to reproduce it;
- any relevant evidence, such as logs or screenshots.
4. Guidelines for researchers
When investigating, we ask that you:
- act in good faith and avoid privacy violations, data destruction or service disruption;
- only interact with accounts you own or have explicit permission to test;
- do not exploit an issue beyond what is necessary to demonstrate it;
- give us reasonable time to respond before any public disclosure.
5. Our commitment to reporters
We will acknowledge your report promptly, keep you informed of our progress, and — where you act in line with this policy — we will not pursue legal action in relation to your research. We're grateful to those who help keep everyone safer.
6. Scope
This policy relates to the responsible handling and reporting of vulnerabilities. It does not authorise testing of any Syntrix client systems; all client testing is governed by a separate Authorisation Agreement.