Eigenexis Systems security
Vulnerability disclosure policy
Policy status · August 6, 2026
Current reporting-channel status
A dedicated monitored security mailbox and encrypted intake channel are being commissioned. They are not represented as operational today. Until an approved channel is published on this page and in security.txt, do not transmit non-public vulnerability details, credentials, personal information, or confidential documents. This missing intake channel blocks real applicant intake, but it does not prevent the static production website from remaining available.
Good-faith testing boundary
Limit research to public website pages, response behavior, and data you own or have explicit permission to use. Use the smallest request volume needed to demonstrate an issue. Stop immediately if testing reaches information belonging to another person or organization.
Prohibited activity
Do not perform denial-of-service testing, destructive scanning, credential attacks, social engineering, spam, data exfiltration, persistence, lateral movement, physical testing, or attempts against unrelated shared hosting infrastructure. Do not alter or delete data and do not upload malware or regulated information.
Information to preserve for a future report
Record the affected canonical URL, observation time, browser or protocol context when relevant, minimal reproduction steps, expected versus observed behavior, and a concise impact assessment. Redact tokens and personal data. Keep evidence private until a monitored intake channel is published.
Acknowledgment and coordinated disclosure
No acknowledgment or remediation time is promised before the intake channel is operational. Once it is published, reports will be assessed for scope, reproducibility, impact, and coordinated disclosure. Researchers should allow a reasonable remediation period and avoid publishing details that could expose users while a valid issue is being investigated.
Privacy, bounty, and legal boundary
Submit only the minimum information required to explain a finding. Eigenexis Systems does not currently offer a bug bounty and this page does not promise payment, safe harbor, immunity, or legal protection. Testing must remain lawful and within the authorized boundaries stated above.