XECbuild
Request Assessment
Security

Security contact

XECbuild does not currently operate a vulnerability disclosure programme or a bug bounty. This page exists so that position is stated plainly rather than left to be guessed at.

No disclosure programme

We are not running a VDP. There is no safe harbour, no pre-authorisation to test, no scope document and no bounty. Nothing on this page should be read as permission to probe, scan, fuzz or otherwise interact with https://xecbuild.com or any system that serves it beyond ordinary use of the website.

Unsolicited testing against our infrastructure is unauthorised access. We log it, and we treat it the same way our clients would. If that changes and we open a programme, it will be announced here and in /.well-known/security.txt.

Client systems are never in scope

Any host, application or domain you find referenced through us belongs to a client and is covered by a separate agreement with its own rules of engagement. We cannot authorise testing against them and neither can you. Please do not try.

If you already know about something

If you have come across a genuine security issue in our own systems - incidentally, or in the course of using the site normally - we do want to hear about it. Use the contact form, or write to [email protected], and describe what you found and how you came across it.

We will read it and we will act on it. We are not offering payment, we are not committing to a response time, and we are not granting retroactive authorisation for testing that produced the report. What we will do is fix the problem, and credit you if you would like to be credited.

Not of interest

Scanner output with no demonstrated impact, missing headers with no exploitable consequence, weak ciphers on endpoints that carry nothing, self-XSS, social engineering of our staff or suppliers, physical attacks, and denial of service. Reports consisting of a tool's exported findings will not receive a reply.

Our own testing

Everything we do for clients happens under a signed agreement with a defined scope, an agreed window and named points of contact. We do not test systems we have not been engaged to test, and we do not accept work against a target the client cannot demonstrate they control. Our approach to that is set out in our acceptable use policy.