Applies to braxhedge.co and Platform services
As part of Braxhedge’s commitment to keeping your account and information safe, if you think you have spotted a potential security issue with any of our services, we welcome your feedback. Please email support@braxhedge.co immediately.
1. Guidelines
Working with skilled security researchers is important for identifying weaknesses in technology. If you discover a vulnerability in our systems or products, disclose it responsibly. We will work with you to understand the scope and address concerns promptly. Vulnerability disclosures are a high priority.
2. Disclosure policy
While researching, please refrain from:
- Denial of service
- Spamming
- Social engineering (including phishing) of Braxhedge staff, contractors, or users
- Physical attempts against Braxhedge property or data centres
- Unauthorized access to data you do not own
- Reports of missing best practices without evidence of a security vulnerability
- Use of a known-vulnerable library without evidence of exploitability
3. Expectations
- Let us know as soon as possible upon discovery of a potential issue.
- Provide a reasonable amount of time to resolve the issue before public or third-party disclosure.
- Make a good-faith effort to avoid privacy violations, data destruction, and service interruption. Only interact with accounts you own.
4. Out of scope
- Reports from automated tools or scans alone
- Missing cookie flags on non-sensitive cookies
- Insecure SSL/TLS ciphers without a working proof of concept
- Exposure of non-sensitive data on mobile devices
- Missing security headers that do not lead directly to a vulnerability, including CSP
5. Third-party bugs
If a report affects a third-party library, external project, or vendor, we may forward details to that party. We will coordinate where possible and will not share your name with third parties without approval.
6. Reporting a vulnerability
Send reports to support@braxhedge.co. Include:
- Description of the location and potential impact
- Detailed reproduction steps; carefully labeled proof of concept where helpful
- Technical information needed to reproduce the issue
- Optional contact handle for follow-up