Responsible Disclosure
Found a vulnerability? How to report it, what we commit to in return, and what is out of scope.
Last updated August 2026
This explains how to report a security problem with this site, and what we commit to in return — acknowledgement within two working days, an assessment within ten, and no legal action for good-faith research within stated bounds. It covers vulnerability reports specifically. It does not cover general security questions, which the Security page covers, and it does not offer a paid bounty — we say so rather than implying a programme we do not run.
If you have found a security problem with this site, we want to hear about it, and we will not treat you as a threat for telling us.
How to report it
Email us with what you found, how to reproduce it, and what you believe the impact is. If you would like to encrypt the report, ask and we will send a key.
Please include enough detail for us to reproduce the issue. A report we cannot reproduce is one we cannot fix.
What we commit to
- An acknowledgement within two working days, from a person rather than an autoresponder.
- An assessment and a plan within ten working days.
- Progress updates while we work on it, rather than silence until it is fixed.
- Credit on this page if you want it, and none if you would rather stay anonymous.
- No legal action against you for good-faith research within the boundaries below.
Staying within bounds
- Do not access, modify or delete data that is not yours.
- Do not degrade the service for other people — no denial of service, no bulk automated scanning.
- Do not use social engineering against us or anyone who works with us.
- Do not test physical security.
- Give us reasonable time to fix the issue before publishing. We will agree a date with you rather than asking for indefinite silence.
What is out of scope
- Reports generated entirely by an automated scanner with no demonstrated impact.
- Missing security headers with no demonstrated exploit path.
- Issues in third-party services we do not control.
- Rate limiting on public pages.
- Self-XSS, or anything requiring an already-compromised device.
We will still read these. We may not act on them, and we will tell you which it is rather than leaving you waiting.
We do not pay bounties
We are a small firm and would rather say that up front than imply a programme we do not run. What you get is a fast, human response, a fix, and public credit if you want it.
Credit
Nobody has reported an issue yet. When someone does and wants credit, their name goes here.
Contact us
To report a security issue:
- XONIK
- 3/3B, Saket Nagar
- Bhopal, Madhya Pradesh 462024
- India
- Email: security@xonik.com
We do not run a paid bounty programme, and this page does not imply one. It does not cover general security questions or our broader practices — see the Security page for those. And it does not cover reports with no demonstrated impact, issues in third-party services we do not control, or physical security testing — see "What is out of scope" above for the full list.
Questions we get asked
Questions about this policy
How quickly will you respond?
Two working days for an acknowledgement, ten for an assessment and a plan. From a person, not an autoresponder.
Do you pay for vulnerability reports?
No. We do not run a bounty programme, and we would rather say so than imply one.
Will you take legal action against me?
Not for good-faith research within the boundaries on this page.
Can I publish what I found?
Yes, after we have had reasonable time to fix it. We will agree a date with you rather than asking for indefinite silence.
What if my report is out of scope?
We will still read it and we will tell you it is out of scope, rather than leaving you waiting for a reply.