Coordinated Vulnerability Disclosure Policy
Last updated: 21 May 2026
TriStiX S.L. (NIF B-26925016) is committed to the security of our products and our customers. We welcome responsible security research and coordinated vulnerability disclosure.
1. Safe Harbor
We will not initiate legal action against security researchers who:
- Act in good faith and in accordance with this policy
- Avoid privacy violations, data destruction, and service disruption
- Report vulnerabilities promptly and do not publicly disclose before coordinated resolution
- Do not exploit vulnerabilities beyond the minimum necessary to demonstrate the issue
This safe-harbor commitment is made in accordance with ISO/IEC 29147 (Vulnerability Disclosure) and the principles of coordinated vulnerability disclosure. We consider authorized security research conducted under this policy to be:
- Authorized with respect to any applicable anti-hacking laws
- Authorized with respect to any relevant anti-circumvention laws
- Exempt from restrictions in our Terms of Service that would otherwise prohibit security testing
If legal action is initiated by a third party against you for activities conducted in compliance with this policy, we will take steps to make it known that your actions were conducted in accordance with this policy.
2. Scope
In Scope
- NetSenX web application:
app.netsenx.com - NetSenX marketing site:
netsenx.com - NetSenX API:
api.netsenx.com - NetSenX documentation:
docs.netsenx.com - Open-source repositories under
github.com/netsenx
Out of Scope
- Third-party services and integrations (Stripe, PostHog, Calendly, Cloudflare)
- Physical security of offices or data centers
- Social engineering attacks against employees or customers
- Denial-of-service (DoS/DDoS) attacks
- Automated scanning that degrades service performance
3. How to Report
Email: [email protected]
PGP Key: Available at https://netsenx.com/.well-known/security.txt
Please include in your report:
- Description of the vulnerability
- Steps to reproduce (proof of concept preferred)
- Impact assessment — What could an attacker achieve?
- Affected component — URL, API endpoint, or repository
- Your contact information for follow-up
4. Response Timeline
| Action | Timeline |
|---|---|
| Acknowledgment of report | Within 2 business days |
| Initial triage and severity assessment | Within 5 business days |
| Status update to reporter | Within 10 business days |
| Target remediation (Critical/High) | Within 30 days |
| Target remediation (Medium/Low) | Within 90 days |
| Coordinated public disclosure | After fix is deployed, by mutual agreement |
5. CRA Art. 13 Compliance
In accordance with the Cyber Resilience Act (CRA) Art. 13, TriStiX S.L.:
- Maintains this publicly accessible vulnerability disclosure policy
- Designates a single point of contact for vulnerability reports: [email protected]
- Commits to timely remediation and transparent communication
- Reports actively exploited vulnerabilities to ENISA within 24 hours as required
- Provides security updates free of charge for the supported lifetime of the product
6. Rewards
We offer recognition and rewards for qualifying vulnerability reports at our discretion:
| Severity | Recognition |
|---|---|
| Critical (RCE, auth bypass, data breach) | Hall of Fame + monetary reward (up to EUR 2,000) |
| High (privilege escalation, SSRF, stored XSS) | Hall of Fame + monetary reward (up to EUR 1,000) |
| Medium (CSRF, information disclosure) | Hall of Fame |
| Low (minor information leakage, best practice) | Acknowledgment |
Exclusions from Rewards
- Issues already known or reported by another researcher
- Vulnerabilities requiring physical access
- Issues in third-party dependencies with published CVEs and available patches
- Reports from automated tools without manual validation
- Out-of-scope items as defined in Section 2
7. Researcher Obligations
When conducting security research, you must:
- Not access, modify, or delete data belonging to other users
- Not degrade the availability or performance of the service
- Not conduct research on production systems if a staging environment is available
- Stop testing and report immediately if you encounter personal data
- Follow applicable laws in your jurisdiction
8. Contact
- Security reports: [email protected]
- General security questions: [email protected]
- security.txt: https://netsenx.com/.well-known/security.txt
TriStiX S.L. — NIF B-26925016 Registered in the Registro Mercantil de Alicante, Spain