Vulnerability Disclosure Policy
At Proxidize Ltd, ensuring the safety and security of our customers, employees, and products is paramount. We appreciate the security community’s efforts in responsibly identifying and reporting vulnerabilities. This policy outlines the procedures and guidelines for submitting vulnerabilities to us. By submitting a vulnerability report, you acknowledge that you’ve read, understood, and agree to adhere to this policy.
On this page
Scope
You are authorized to test the following assets:
- proxidize.com and all its subdomains.
- proxi.es and all its subdomains.
Out-of-Scope: Any services or domains not explicitly listed above.
Prohibited Activities
To protect our users and infrastructure, the following actions are strictly prohibited:
- Denial of Service (DoS) or any form of service disruption.
- Brute forcing or excessive rate-limiting tests.
- Automated scans causing high volumes of traffic.
- Social engineering attacks on employees, contractors, or partners.
- Any activity resulting in disruption of our services or operations.
Reporting a Vulnerability
Submit your detailed vulnerability reports to: [email protected]
Reporting Requirements:
Ensure your report includes:
- Clear and detailed descriptions of the vulnerability.
- Impact and risk assessments.
- Steps to reproduce the vulnerability.
- Proof-of-concept, ideally including screenshots or video.
- Specific URLs and IP addresses involved during testing.
- Any relevant information on how the vulnerability was discovered.
- Your intended plan or expectations for public disclosure (subject to mutual agreement).
Reports should be written clearly in English. Reports containing proof-of-concept code and detailed reproduction steps will receive priority.
All communication regarding a report must go through [email protected]. Please do not contact our support team or any other channel to ask about the status of your report. Doing so may result in your report being closed without further review.
Our Commitment
Upon receipt of your report, Proxidize Ltd will:
- Acknowledge receipt of your submission as soon as reasonably practicable.
- Provide an initial substantive response or status update within 30 calendar days.
- Communicate with you in good faith throughout the validation and remediation process, where appropriate.
- Notify you after we have validated and remediated the reported issue, where appropriate.
No Bug Bounty Program
Proxidize Ltd does not operate a bug bounty program. We do not offer monetary rewards, credit, or any other compensation for vulnerability reports. Good-faith reports are triaged, validated, and remediated, and reporters are kept informed as set out in Our Commitment above.
We appreciate your commitment to responsible disclosure and the enhancement of security for Proxidize Ltd and its customers.