Responsible Disclosure

Last updated: August 7, 2026

Our position

If you have identified a security vulnerability in a system we control, we want to hear about it. We will take your report seriously, act on it, and credit you if you would like.

Scope

In scope — these Secalyx-controlled assets only

  • secalyx.com/ and www.secalyx.com
  • The web application and configuration deployed at those hostnames
  • Public DNS records for secalyx.com/ and the email authentication configuration (SPF, DKIM, DMARC) published for that domain

Out of scope

  • Client environments. If you have found a vulnerability in a system belonging to one of our clients, report it to that organization. We cannot authorize testing of systems we do not own
  • Our providers' platforms, including Microsoft, Hostinger and GoDaddy. Our email is hosted by Microsoft and our website by Hostinger. Testing their platforms is not authorized here — report to them directly
  • Shared infrastructure and other customers. Our website runs on shared hosting. Any activity affecting other tenants is unauthorized
  • Any hostname not listed above
  • Automated scanner output without a demonstrated exploit path
  • Missing security headers, TLS configuration preferences, and similar observations with no demonstrable impact
  • Social engineering of our people, clients or suppliers
  • Physical security
  • Denial of service, volumetric testing, or resource exhaustion

Rules of engagement

Please do not:

  • Access, modify, delete, copy, retain or exfiltrate data belonging to us or anyone else
  • Attempt credential stuffing, password spraying, brute force, or any attack against accounts
  • Escalate privileges beyond the minimum needed to demonstrate an issue
  • Move laterally, establish persistence, or install anything
  • Upload or deploy malware, web shells or backdoors
  • Send spam or use our systems to contact third parties
  • Access or attempt to access any account that is not your own
  • Conduct high-volume or aggressive automated testing
  • Pivot into provider infrastructure or systems belonging to other customers

If personal data or confidential information becomes visible, stop immediately, do not retain or record it, and tell us in your report.

How to report

Email info@secalyx.com with the subject line Security Disclosure.

Do not include technical detail, proof of concept, or captured data in your first message. Tell us you have something to report and we will respond to agree a secure channel before you share specifics.

Our machine-readable contact information is at /.well-known/security.txt.

What you can expect

  • Acknowledgement as promptly as we are able. We are a small practice and do not commit to a fixed window, but security reports are treated as a priority
  • An assessment of the issue and what we intend to do
  • Updates as remediation progresses
  • Public credit if you would like it — tell us how you wish to be identified

We do not operate a bug bounty and do not offer financial rewards. We say so plainly so nobody invests time expecting one.

Good-faith research

If you conduct security research in good faith, in full compliance with this policy, and only against the specific assets listed as in scope, Secalyx Technologies LLP will not initiate legal action against you in relation to that research.

This statement is given by Secalyx Technologies LLP alone. It does not bind our service providers, our clients, any other third party, or any regulatory or law enforcement authority. It does not authorize activity outside this policy and does not affect obligations arising under applicable law.

If a third party initiates action against you in relation to research that fully complied with this policy, we will, on request, confirm that the activity was conducted under it.

Contact

info@secalyx.com