xsenv

Found a hole? Tell us.

We build systems meant to answer nobody. If you found something that answers, or that lets someone in, we want to hear it first, and we will treat you as a colleague, not a threat.

How to report.

Write to security@xsenv.com, in English or Romanian. Tell us what you found, where, how to reproduce it, and what you think it allows. A proof of concept helps; data you should not have does not. If the details are too sensitive for ordinary e-mail, say so in a first message and we will agree on an encrypted channel. The same address is in our security.txt.

What is in scope.

Each customer environment runs on servers the customer controls, and its data is theirs. Do not test one without that customer's written authorisation. A weakness you find in the software that runs them is in scope: report it to us, and we will handle it for every customer at once.

What we commit to.

We are in early access and pay no bounties yet. We still say thank you properly.

Good faith.

If you act in good faith and within these rules, we will not take legal action against you or ask anyone else to, and we will say so to anyone who asks. The rules:

Advisories.

None so far. Fixed weaknesses that affected customers or published releases will be listed here, with what to do and who found them.