Coordinated disclosure helps protect visitors.
XFind welcomes good-faith reports that help improve security while respecting privacy, safety, and service availability.
Purpose
This policy explains how security researchers can responsibly report potential vulnerabilities affecting XFind.tech.
Scope
The scope is limited to public XFind.tech web experiences and public inquiry flows. Testing must be safe, limited, and must not affect visitors, customer information, service availability, or third-party systems.
What Researchers May Test
- Publicly available XFind web pages.
- Public forms you are authorized to use.
- Issues that can be demonstrated without accessing customer information.
- Findings that are reported privately and responsibly.
What Researchers May Not Do
- Denial of service or traffic flooding.
- Social engineering of XFind, visitors, partners, or employees.
- Physical attacks or in-person attempts.
- Accessing, modifying, deleting, or copying customer information.
- Persistence, backdoors, malware, or destructive actions.
- Testing third-party services without authorization.
- Public disclosure before XFind has had a reasonable opportunity to review.
Responsible Disclosure Expectations
Please report findings privately, include clear reproduction details, avoid unnecessary access to data, and allow XFind a reasonable opportunity to investigate before any public discussion.
Thank You
XFind appreciates responsible researchers who act in good faith and help strengthen safety for visitors.
