Al momento questa pagina è disponibile solo in inglese.
Responsible Disclosure
Last updated: March 2026 · Version: 1.0 · Controller / Processor: TriStiX S.L.
1. Summary
- Where to report: [email protected] (PGP available on request) or via Intigriti once the programme is open.
- Acknowledgement: within 2 business days.
- Triage decision: within 5 business days.
- Disclosure timeline: 90 days coordinated, extendable by mutual agreement.
- Safe harbor: good-faith, in-scope research is welcome and will not be pursued legally.
2. Scope
The following assets are in scope for this programme:
- NetSenX cloud platform —
*.netsenx.com(landing, dashboard, API endpoints) - NetSenX agent — published binaries and source available to enrolled customers
- Public assets — security policies, security.txt, JSON-LD, sitemap
3. Out of Scope
- Findings on third-party services that we use (e.g., Calendly, sub-processors)
- Findings that require physical access to a customer’s infrastructure or social engineering of TriStiX staff
- Denial-of-service testing (please describe the issue without executing the attack)
- Spam, vulnerability scanners’ unreviewed output, missing best-practice headers
- Self-XSS and clickjacking on pages without sensitive actions
- Issues already publicly known or reported by another researcher
4. How to Report
- Email [email protected] from an address we can reply to. Request our PGP key in your first message if you wish to encrypt the report.
- Alternatively, file the report on Intigriti once the public programme is open. Pre-launch invites are offered to researchers who report a valid in-scope issue via email.
- Use the machine-readable security contact at /.well-known/security.txt if you discover this page via automated tooling.
5. What to Include
- Concise description of the vulnerability and the affected asset
- Step-by-step reproduction (CLI commands, request/response, screenshots)
- Impact assessment (what an attacker can do)
- Suggested fix or mitigation, if you have one
- Your preferred name / handle for the Hall of Fame (optional)
6. Safe Harbor
We will not initiate or support legal action against researchers who:
- Act in good faith and follow this policy
- Stay within the in-scope assets listed in Section 2
- Do not exfiltrate, destroy, or modify data beyond what is strictly necessary to demonstrate the vulnerability
- Do not disrupt service for other users
- Privately disclose the issue to us first and give us a reasonable opportunity to remediate
Safe harbor does not cover out-of-scope actions, attacks on infrastructure we do not control, or violations of applicable criminal law (including, in Spain, Articles 197–201 of the Penal Code).
7. Service Level Agreement
| Stage | Target |
|---|---|
| Acknowledgement | 2 business days |
| Triage decision | 5 business days |
| Fix — Critical (CVSS 9.0–10.0) | 7 days |
| Fix — High (CVSS 7.0–8.9) | 30 days |
| Fix — Medium (CVSS 4.0–6.9) | 90 days |
| Fix — Low (CVSS 0.1–3.9) | 180 days |
8. Coordinated Disclosure Timeline
We target 90 days from triage to coordinated public disclosure. The window can be extended by mutual agreement if a fix requires additional time (e.g., complex cross-tenant change, supply-chain coordination). We commit to a public advisory once the fix is shipped and customer rollouts are complete.
9. Recognition
- Hall of Fame: we publicly recognise researchers (with their consent) on a page published at /security/hall-of-fame (in setup for V1b).
- Cash bounty: available via Intigriti once the public programme is open. During the soft-launch phase we offer retroactive bounty consideration for valid in-scope reports.
- Swag & thanks: at our discretion, we may send swag or written thanks for impactful reports.
10. Out of Bounty (Will Be Closed Without Reward)
- Theoretical issues without a working proof-of-concept
- Reports based solely on automated scanner output without analysis
- Best-practice or hardening suggestions with no measurable security impact
- Issues already in our public backlog or known to the security team
For more context on our broader security posture, see the /security page.