Responsible Vulnerability Disclosure Policy
We welcome good-faith reports of security vulnerabilities in our own website, portal and infrastructure. This policy explains how to report responsibly and what protection we offer researchers who follow it.
In scope
- pristinelextech.example public website and client portal
- Publicly accessible APIs on our infrastructure
Client systems we consult on are not in scope of this policy — testing those requires separate written authorisation from that client, per our Professional Disclaimer.
Ground rules
- No automated scanning that degrades service availability.
- No access to, modification of, or exfiltration of data beyond what is strictly necessary to demonstrate the issue.
- No social engineering, phishing, or physical-security testing against our staff or premises.
- Report privately to us before any public disclosure; we aim to acknowledge within 5 business days and keep you updated on remediation.
How to report
Email security@pristinelextech.example with a clear description, steps to reproduce, and impact. Encrypt sensitive details if possible.
What we offer
We will not pursue legal action against researchers who make a good-faith effort to comply with this policy. We do not currently operate a paid bug-bounty programme; we will credit researchers who wish to be credited once a fix ships.