Vulnerability disclosure policy
Netix Digital Ltd runs IT and security for other businesses, so we take reports about our own systems seriously. If you believe you have found a security vulnerability in one of our websites or services, this page explains how to tell us and what happens next. It is also published in machine-readable form at /.well-known/security.txt.
1. How to report
Email our Security and Network Operations Centre:
Email: [email protected]
Please include the address or service affected, the steps to reproduce what you found, what you believe the impact is, and how we can contact you. Screenshots or a short recording help. Do not include customer data in the report beyond the minimum needed to show the issue.
2. What we do with a report
- We acknowledge every report within 2 working days.
- We tell you whether we can reproduce the issue, and how serious we think it is, within 10 working days.
- We fix confirmed issues in an order set by their severity and keep you informed of progress if you ask.
- We ask you to give us a reasonable time to fix an issue before you talk about it publicly, and we will agree that time with you rather than impose it.
3. Scope
This policy covers systems that Netix Digital Ltd owns and operates, including:
- netix.digital and its subdomains
- pulse.netix.digital, the Netix Pulse client portal
- Netix Foundry, our website platform, where we host it
It does not cover systems we manage on behalf of our clients: those belong to the client, and a vulnerability in one of them should be reported to that organisation. If you are not sure whose system it is, email us and we will point you to the right place. Third-party services we use (Microsoft, Netlify, Cloudflare, Cal.com and similar) have their own disclosure programmes.
4. Rules for testing
While looking for or confirming a vulnerability, please:
- do not access, change or delete data that is not yours, and stop as soon as you have enough to demonstrate the issue
- do not run denial-of-service tests, automated scanning at volume, or anything that degrades the service for other users
- do not use social engineering, phishing or physical attacks against our staff, offices or clients
- do not use a vulnerability to pivot into other systems
- keep anything you did see confidential and delete it once the issue is confirmed
5. Good-faith research
If you follow this policy, we consider your research to be authorised and conducted in good faith. We will not take legal action against you or refer you to law enforcement for it, and we will work with you if a third party does. This does not apply to anyone who breaks the rules above, extorts, or uses what they find for any purpose other than reporting it to us.
6. Recognition
We do not run a paid bug bounty. We are happy to credit you by name or handle once the issue is fixed if you would like that, and we say thank you properly to people who help us keep our clients safe.