Vulnerability Reporting Policy
XPI Vulnerability Reporting Policy
The XPI security team acknowledges the valuable role that independent security researchers play in Internet security. Keeping our customers' data secure is our number-one priority, and we encourage responsible reporting of any vulnerabilities that may be found in our site or application. XPI is committed to working with the security community to verify and respond to any potential vulnerabilities that are reported to us. Additionally, XPI pledges not to initiate legal action against security researchers for penetrating or attempting to penetrate our systems as long as they adhere to the conditions below.
Testing for security vulnerabilities:
Conduct all vulnerability testing of our online services to minimize the risk to our customers' data.
Reporting a potential security vulnerability:
- Privately share details of the suspected vulnerability with XPI by sending an email to security@disclosurenet.com
- Provide full details of the suspected vulnerability so the XPI security team may validate and reproduce the issue
XPI does not permit the following types of security research:
- Causing, or attempting to cause, a Denial of Service (DoS) condition
- Accessing, or attempting to access, data or information that does not belong to you
- Destroying or corrupting, or attempting to destroy or corrupt, data or information that does not belong to you
The XPI security team commitment:
To all security researchers who follow this XPI Vulnerability Reporting Policy, the XPI security team commits to the following.
- To respond in a timely manner, acknowledging receipt of your report
- To provide an estimated time frame for addressing the vulnerability
- To notify the reporting individual when the vulnerability has been fixed
No compensation:
XPI does not compensate people for reporting a security vulnerability, and any requests for such compensation will be considered a violation of the conditions above. In such an event, XPI reserves all of its legal rights.
"DisclosureNet is simply the best disclosure research solution available on the market today; with global data coverage that includes Canada, the US, UK, and now Australia. Its power and ease of use ensures we can access and stay informed of key competitive information - such as mining costs, mine reserves and peer group activities - VERY QUICKLY. As a result, DisclosureNet generates a fast payback and sustainably large ROI in terms of time and cost savings."
Lincoln Greenidge, Corporate Controller
See how DisclosureNet helps our clients to find the
public company information they need, when they need it.
Learn More