Responsible Vulnerability Disclosure Policy

We welcome good-faith reports of security vulnerabilities in our own website, portal and infrastructure. This policy explains how to report responsibly and what protection we offer researchers who follow it.

In scope

  • pristinelextech.example public website and client portal
  • Publicly accessible APIs on our infrastructure

Client systems we consult on are not in scope of this policy — testing those requires separate written authorisation from that client, per our Professional Disclaimer.

Ground rules

  • No automated scanning that degrades service availability.
  • No access to, modification of, or exfiltration of data beyond what is strictly necessary to demonstrate the issue.
  • No social engineering, phishing, or physical-security testing against our staff or premises.
  • Report privately to us before any public disclosure; we aim to acknowledge within 5 business days and keep you updated on remediation.

How to report

Email security@pristinelextech.example with a clear description, steps to reproduce, and impact. Encrypt sensitive details if possible.

What we offer

We will not pursue legal action against researchers who make a good-faith effort to comply with this policy. We do not currently operate a paid bug-bounty programme; we will credit researchers who wish to be credited once a fix ships.