Legal

Security policy.

Keeping accounts and information safe — and how to report potential security issues.

Applies to braxhedge.co and Platform services

As part of Braxhedge’s commitment to keeping your account and information safe, if you think you have spotted a potential security issue with any of our services, we welcome your feedback. Please email support@braxhedge.co immediately.

1. Guidelines

Working with skilled security researchers is important for identifying weaknesses in technology. If you discover a vulnerability in our systems or products, disclose it responsibly. We will work with you to understand the scope and address concerns promptly. Vulnerability disclosures are a high priority.

2. Disclosure policy

While researching, please refrain from:

  • Denial of service
  • Spamming
  • Social engineering (including phishing) of Braxhedge staff, contractors, or users
  • Physical attempts against Braxhedge property or data centres
  • Unauthorized access to data you do not own
  • Reports of missing best practices without evidence of a security vulnerability
  • Use of a known-vulnerable library without evidence of exploitability

3. Expectations

  • Let us know as soon as possible upon discovery of a potential issue.
  • Provide a reasonable amount of time to resolve the issue before public or third-party disclosure.
  • Make a good-faith effort to avoid privacy violations, data destruction, and service interruption. Only interact with accounts you own.

4. Out of scope

  • Reports from automated tools or scans alone
  • Missing cookie flags on non-sensitive cookies
  • Insecure SSL/TLS ciphers without a working proof of concept
  • Exposure of non-sensitive data on mobile devices
  • Missing security headers that do not lead directly to a vulnerability, including CSP

5. Third-party bugs

If a report affects a third-party library, external project, or vendor, we may forward details to that party. We will coordinate where possible and will not share your name with third parties without approval.

6. Reporting a vulnerability

Send reports to support@braxhedge.co. Include:

  • Description of the location and potential impact
  • Detailed reproduction steps; carefully labeled proof of concept where helpful
  • Technical information needed to reproduce the issue
  • Optional contact handle for follow-up