Skip to content
Menu

Report a vulnerability

How to tell us something is broken.

Write to security@hellofixi.com. You will have an acknowledgement from a person within 2 working days. There is no bounty, and there is safe harbour for anyone who reports in good faith.

Version 1.0. Effective . Last reviewed .

1. Safe harbour

The commitment that matters most

No action will be taken against anyone who reports in good faith and who does not access or alter data that is not theirs. That is the same sentence as the one in the machine-readable file, and it is the commitment worth reading twice, because a researcher deciding whether to tell us is weighing exactly this.

If you are unsure whether something you are about to try crosses that line, ask first at security@hellofixi.com. Asking has never counted against anyone.

2. What is in scope

This website, hellofixi.com, and odel-labs, which Fixi Group Limited operates. Anything that lets somebody read, change or delete data they should not reach, bypass authentication, or act as another account is in scope and is worth sending even if you are not certain.

3. What is out of scope

Positions, not judgements on your report

  1. Volumetric testing, denial of service, or anything that degrades the service for other people.
  2. Social engineering of anyone connected to the company, and physical attempts on the registered office.
  3. Accessing, modifying, exfiltrating or retaining data belonging to somebody else. Stop at the point you have proved the issue exists.
  4. Automated scanner output sent without a working demonstration. A missing header with no path to impact is a note rather than a vulnerability, and it is still welcome, it is just not treated as urgent.

4. What to send

Enough to reproduce it: the address, the steps, what you expected and what happened instead. A short recording beats a long description. English is the preferred language. If you want to encrypt the report, say so in the first message and a key will come back.

5. What happens next

Acknowledged within 2 working days

  1. A person acknowledges the report within 2 working days. Not an auto-responder.
  2. The acknowledgement says whether the issue is reproduced, and gives a date by which you will hear the assessment. No fix window is promised here, because none has been measured, and a missed promise is worse than an honest date.
  3. You are told when it is fixed. If you want credit you will be asked first, and nothing is published about your report without your agreement.
  4. If it turns out not to be a vulnerability, you are told why rather than left without a reply.

6. The machine-readable version

The same contact and terms are published at /.well-known/security.txt, which carries an expiry date. If that file has expired, the company has stopped paying attention and this page should be treated with the same suspicion.

security.txt