Responsible Disclosure
Last updated: August 7, 2026
Our position
If you have identified a security vulnerability in a system we control, we want to hear about it. We will take your report seriously, act on it, and credit you if you would like.
Scope
In scope — these Secalyx-controlled assets only
secalyx.com/ and www.secalyx.com- The web application and configuration deployed at those hostnames
- Public DNS records for secalyx.com/ and the email authentication configuration (SPF, DKIM, DMARC) published for that domain
Out of scope
- Client environments. If you have found a vulnerability in a system belonging to one of our clients, report it to that organization. We cannot authorize testing of systems we do not own
- Our providers' platforms, including Microsoft, Hostinger and GoDaddy. Our email is hosted by Microsoft and our website by Hostinger. Testing their platforms is not authorized here — report to them directly
- Shared infrastructure and other customers. Our website runs on shared hosting. Any activity affecting other tenants is unauthorized
- Any hostname not listed above
- Automated scanner output without a demonstrated exploit path
- Missing security headers, TLS configuration preferences, and similar observations with no demonstrable impact
- Social engineering of our people, clients or suppliers
- Physical security
- Denial of service, volumetric testing, or resource exhaustion
Rules of engagement
Please do not:
- Access, modify, delete, copy, retain or exfiltrate data belonging to us or anyone else
- Attempt credential stuffing, password spraying, brute force, or any attack against accounts
- Escalate privileges beyond the minimum needed to demonstrate an issue
- Move laterally, establish persistence, or install anything
- Upload or deploy malware, web shells or backdoors
- Send spam or use our systems to contact third parties
- Access or attempt to access any account that is not your own
- Conduct high-volume or aggressive automated testing
- Pivot into provider infrastructure or systems belonging to other customers
If personal data or confidential information becomes visible, stop immediately, do not retain or record it, and tell us in your report.
How to report
Email info@secalyx.com with the subject line Security Disclosure.
Do not include technical detail, proof of concept, or captured data in your first message. Tell us you have something to report and we will respond to agree a secure channel before you share specifics.
Our machine-readable contact information is at /.well-known/security.txt.
What you can expect
- Acknowledgement as promptly as we are able. We are a small practice and do not commit to a fixed window, but security reports are treated as a priority
- An assessment of the issue and what we intend to do
- Updates as remediation progresses
- Public credit if you would like it — tell us how you wish to be identified
We do not operate a bug bounty and do not offer financial rewards. We say so plainly so nobody invests time expecting one.
Good-faith research
If you conduct security research in good faith, in full compliance with this policy, and only against the specific assets listed as in scope, Secalyx Technologies LLP will not initiate legal action against you in relation to that research.
This statement is given by Secalyx Technologies LLP alone. It does not bind our service providers, our clients, any other third party, or any regulatory or law enforcement authority. It does not authorize activity outside this policy and does not affect obligations arising under applicable law.
If a third party initiates action against you in relation to research that fully complied with this policy, we will, on request, confirm that the activity was conducted under it.
Contact
info@secalyx.com