Home /Responsible disclosure
Security · /responsible-disclosure

Responsible disclosure of vulnerabilities

If you have found a possible XDBay vulnerability, report it to us through a protected channel. Do not use it to access other people's data, alter balances, disrupt the service or gain any benefit.

We value the help of security researchers and aim to respond to properly prepared reports.

DEMO · #VDP
disclosure

Vulnerability report

Channelsecurity email
PGPTO APPROVE
Safe harborTO APPROVE
Response timeTO APPROVE
Bug bountyTO APPROVE
Updated 20 July 2026Author: XDBay editorial teamDisclosure policy
Rules

How to report responsibly

Three rules that make a report useful and safe for everyone involved.

Do no harm

Do not use the vulnerability to access other people's data, alter balances or disrupt the service. Work only with your own test accounts.

Include the details

Describe the reproduction steps, the affected URL or component, the expected impact and safe proof of the issue.

Use a protected channel

Send the technical description through the approved security contact. Use a PGP key where possible.

Process

What happens after a report

1

Intake

We confirm receipt of the report through the protected channel and log the case.

2

Review

The team reproduces the issue and assesses its impact and priority. Where needed, it asks the researcher for details.

3

Remediation

The vulnerability is fixed and the researcher receives feedback. Credit and bug bounty terms follow the programme rules.

Report

Report a vulnerability

Describe the issue in technical terms. Do not attach real third-party data and do not perform destructive actions.

  • Your own test accounts only
  • Reproduction steps and impact
  • Do not disclose the vulnerability publicly before it is fixed
  • The reply comes through a protected channel

Responsible disclosure form

The report goes to the security team.

By submitting the form you agree to our data processing policy and the XDBay terms of service.

What's next: the report reaches the security team. We confirm receipt, reproduce the issue and keep you informed. Please do not disclose the vulnerability publicly before it is fixed.
FAQ

Frequently asked questions

Whether a reward programme exists and on what terms is settled before publication and is marked “TO APPROVE”. Either way, we value well-prepared reports.
Please do not disclose the issue publicly until it has been fixed and the timing has been agreed with the security team.
Response times are fixed in the disclosure policy. Until they are approved, they are marked “TO APPROVE”.

Help make XDBay safer

Report vulnerabilities responsibly through a protected channel — we will investigate and get back to you.