Do no harm
Do not use the vulnerability to access other people's data, alter balances or disrupt the service. Work only with your own test accounts.
If you have found a possible XDBay vulnerability, report it to us through a protected channel. Do not use it to access other people's data, alter balances, disrupt the service or gain any benefit.
We value the help of security researchers and aim to respond to properly prepared reports.
Three rules that make a report useful and safe for everyone involved.
Do not use the vulnerability to access other people's data, alter balances or disrupt the service. Work only with your own test accounts.
Describe the reproduction steps, the affected URL or component, the expected impact and safe proof of the issue.
Send the technical description through the approved security contact. Use a PGP key where possible.
We confirm receipt of the report through the protected channel and log the case.
The team reproduces the issue and assesses its impact and priority. Where needed, it asks the researcher for details.
The vulnerability is fixed and the researcher receives feedback. Credit and bug bounty terms follow the programme rules.
Describe the issue in technical terms. Do not attach real third-party data and do not perform destructive actions.
The report goes to the security team.
Report vulnerabilities responsibly through a protected channel — we will investigate and get back to you.