Please do not open a public issue for a suspected vulnerability. Send a private report to security@xfeatures.net with:
- the affected product, repository, endpoint or version;
- a concise description of the issue and its impact;
- reproducible steps or a minimal proof of concept;
- any mitigations you have identified; and
- a safe way to contact you for follow-up.
Do not include secrets, personal data, production access tokens, destructive payloads or details of a live customer environment unless they are essential to reproduction. If encrypted communication is required, ask for a secure channel in your initial report.
We aim to acknowledge a report within 3 business days, assess its scope, and keep the reporter informed about material progress. Timelines vary with severity, affected systems and the need to coordinate a safe fix.
We ask researchers to give us a reasonable opportunity to remediate the issue before public disclosure. We will not ask for intrusive testing, service disruption, access to other users' data, credential attacks or social engineering.
This policy covers maintained XfeaturesGroup repositories and services that are
explicitly operated by XfeaturesGroup. A repository-specific SECURITY.md
takes precedence where present. Third-party services, archived projects and
unsupported forks may be out of scope.
Security fixes are prioritised for the default branch and currently deployed versions of maintained services. Legacy and archived repositories may receive a mitigation or migration recommendation rather than a backport.
We value good-faith, reproducible reports. Recognition or rewards, where offered, are discretionary and depend on impact, report quality and compliance with this policy. This policy does not authorise testing against systems you do not own or administer.