Legal / Policies

Responsible Vulnerability Disclosure

Last Updated: July 16, 2026

Coordinated disclosure helps protect visitors.

XFind welcomes good-faith reports that help improve security while respecting privacy, safety, and service availability.

Purpose

This policy explains how security researchers can responsibly report potential vulnerabilities affecting XFind.tech.

Scope

The scope is limited to public XFind.tech web experiences and public inquiry flows. Testing must be safe, limited, and must not affect visitors, customer information, service availability, or third-party systems.

What Researchers May Test

  • Publicly available XFind web pages.
  • Public forms you are authorized to use.
  • Issues that can be demonstrated without accessing customer information.
  • Findings that are reported privately and responsibly.

What Researchers May Not Do

  • Denial of service or traffic flooding.
  • Social engineering of XFind, visitors, partners, or employees.
  • Physical attacks or in-person attempts.
  • Accessing, modifying, deleting, or copying customer information.
  • Persistence, backdoors, malware, or destructive actions.
  • Testing third-party services without authorization.
  • Public disclosure before XFind has had a reasonable opportunity to review.

Responsible Disclosure Expectations

Please report findings privately, include clear reproduction details, avoid unnecessary access to data, and allow XFind a reasonable opportunity to investigate before any public discussion.

Thank You

XFind appreciates responsible researchers who act in good faith and help strengthen safety for visitors.