Found a hole? Tell us.
We build systems meant to answer nobody. If you found something that answers, or that lets someone in, we want to hear it first, and we will treat you as a colleague, not a threat.
How to report.
Write to security@xsenv.com, in English or Romanian. Tell us what you found, where, how to reproduce it, and what you think it allows. A proof of concept helps; data you should not have does not. If the details are too sensitive for ordinary e-mail, say so in a first message and we will agree on an encrypted channel. The same address is in our security.txt.
What is in scope.
- xsenv-net: the agent, the control plane, the admin page, the Android app, the installers and the published releases.
- This website, and anything served under xsenv.com or xsenv.net.
- The way we build, sign and deliver our software, and the code that deploys and runs our environments.
- Our own environment, as far as you can reach it from the internet: by design, only WireGuard should answer.
Each customer environment runs on servers the customer controls, and its data is theirs. Do not test one without that customer's written authorisation. A weakness you find in the software that runs them is in scope: report it to us, and we will handle it for every customer at once.
What we commit to.
- A person answers within three working days, and tells you within ten whether we can reproduce it and how serious we think it is.
- We fix what is serious first: an actively exploited or critical weakness as fast as we can, others in our next releases, and we keep you informed until it is fixed.
- We tell the customers it affects what to do, and what we did.
- We agree with you when it becomes public, usually once it is fixed and at most 90 days after your report, sooner if it is exploited in the wild.
- We credit you in the advisory, by name or handle, unless you would rather not be named.
We are in early access and pay no bounties yet. We still say thank you properly.
Good faith.
If you act in good faith and within these rules, we will not take legal action against you or ask anyone else to, and we will say so to anyone who asks. The rules:
- Use only accounts, devices and data that are yours. If you reach anyone else's data, stop, do not keep or share it, and tell us.
- No denial of service, no spam, no social engineering of our people or our customers, no physical access.
- Do not change or destroy anything, and do not keep a foothold once you have shown the weakness.
- Give us a reasonable time to fix it before you speak about it publicly.
Advisories.
None so far. Fixed weaknesses that affected customers or published releases will be listed here, with what to do and who found them.