Coordinated Vulnerability Disclosure Policy

Last updated: 21 May 2026

TriStiX S.L. (NIF B-26925016) is committed to the security of our products and our customers. We welcome responsible security research and coordinated vulnerability disclosure.

1. Safe Harbor

We will not initiate legal action against security researchers who:

  • Act in good faith and in accordance with this policy
  • Avoid privacy violations, data destruction, and service disruption
  • Report vulnerabilities promptly and do not publicly disclose before coordinated resolution
  • Do not exploit vulnerabilities beyond the minimum necessary to demonstrate the issue

This safe-harbor commitment is made in accordance with ISO/IEC 29147 (Vulnerability Disclosure) and the principles of coordinated vulnerability disclosure. We consider authorized security research conducted under this policy to be:

  • Authorized with respect to any applicable anti-hacking laws
  • Authorized with respect to any relevant anti-circumvention laws
  • Exempt from restrictions in our Terms of Service that would otherwise prohibit security testing

If legal action is initiated by a third party against you for activities conducted in compliance with this policy, we will take steps to make it known that your actions were conducted in accordance with this policy.

2. Scope

In Scope

  • NetSenX web application: app.netsenx.com
  • NetSenX marketing site: netsenx.com
  • NetSenX API: api.netsenx.com
  • NetSenX documentation: docs.netsenx.com
  • Open-source repositories under github.com/netsenx

Out of Scope

  • Third-party services and integrations (Stripe, PostHog, Calendly, Cloudflare)
  • Physical security of offices or data centers
  • Social engineering attacks against employees or customers
  • Denial-of-service (DoS/DDoS) attacks
  • Automated scanning that degrades service performance

3. How to Report

Email: [email protected]

PGP Key: Available at https://netsenx.com/.well-known/security.txt

Please include in your report:

  1. Description of the vulnerability
  2. Steps to reproduce (proof of concept preferred)
  3. Impact assessment — What could an attacker achieve?
  4. Affected component — URL, API endpoint, or repository
  5. Your contact information for follow-up

4. Response Timeline

ActionTimeline
Acknowledgment of reportWithin 2 business days
Initial triage and severity assessmentWithin 5 business days
Status update to reporterWithin 10 business days
Target remediation (Critical/High)Within 30 days
Target remediation (Medium/Low)Within 90 days
Coordinated public disclosureAfter fix is deployed, by mutual agreement

5. CRA Art. 13 Compliance

In accordance with the Cyber Resilience Act (CRA) Art. 13, TriStiX S.L.:

  • Maintains this publicly accessible vulnerability disclosure policy
  • Designates a single point of contact for vulnerability reports: [email protected]
  • Commits to timely remediation and transparent communication
  • Reports actively exploited vulnerabilities to ENISA within 24 hours as required
  • Provides security updates free of charge for the supported lifetime of the product

6. Rewards

We offer recognition and rewards for qualifying vulnerability reports at our discretion:

SeverityRecognition
Critical (RCE, auth bypass, data breach)Hall of Fame + monetary reward (up to EUR 2,000)
High (privilege escalation, SSRF, stored XSS)Hall of Fame + monetary reward (up to EUR 1,000)
Medium (CSRF, information disclosure)Hall of Fame
Low (minor information leakage, best practice)Acknowledgment

Exclusions from Rewards

  • Issues already known or reported by another researcher
  • Vulnerabilities requiring physical access
  • Issues in third-party dependencies with published CVEs and available patches
  • Reports from automated tools without manual validation
  • Out-of-scope items as defined in Section 2

7. Researcher Obligations

When conducting security research, you must:

  • Not access, modify, or delete data belonging to other users
  • Not degrade the availability or performance of the service
  • Not conduct research on production systems if a staging environment is available
  • Stop testing and report immediately if you encounter personal data
  • Follow applicable laws in your jurisdiction

8. Contact


TriStiX S.L. — NIF B-26925016 Registered in the Registro Mercantil de Alicante, Spain