Policy
Vulnerability Disclosure
If you have found a weakness in something we operate, we would rather hear it from you than from somebody else. This sets out how, and what we will do about it.
Last reviewed 1 August 2026. Where this document changes materially, the revision date changes with it.
01
How to report
Use the contact page and select a general enquiry, or reply to any correspondence you already have with us. Mark the message clearly as a security report so it is prioritised correctly.
Please include, where you can:
- the affected address or endpoint
- a description of the issue and its likely impact
- steps sufficient to reproduce it
- the approximate date and time you observed it
- whether you believe it has been exploited by anyone
A concise report with reproduction steps is worth considerably more than an automated scanner output. If you have only the latter, send it anyway — but expect the assessment to take longer.
02
What is in scope
The ixseo.com website and the API endpoints it uses. Issues we are particularly interested in:
- anything that causes the analysis fetcher to reach a private, internal or metadata address
- a way to bypass the redirect guard, the byte cap, the timeout or the content-type restriction
- exposure of an API key or any server-side secret to the browser
- access to another visitor’s analysis result, snapshot or enquiry
- injection of any kind, including into the report rendering path
- a way to make the service issue requests at a volume that would burden a third-party website
- circumvention of the rate limit in a way that enables abuse
03
What is out of scope
- Missing security headers on their own. We are aware of the category and treat it as hardening rather than as a vulnerability.
- Results from an automated scanner with no demonstrated impact.
- Denial of service, volumetric testing or anything that would degrade the service for others. Please do not attempt these.
- Social engineering of our people or our suppliers.
- Physical security, and anything concerning premises.
- Issues in third-party services we consume, which should be reported to their operators.
- Anything requiring a compromised device or a heavily non-default browser configuration.
- Reports about a website analysed throughIXSEO. Those belong with that website’s operator, not with us.
04
What we ask of you
- Stay within scope, and stop as soon as you have established that an issue exists.
- Do not access, modify or retain data belonging to anyone else. If you encounter it accidentally, stop and tell us what you saw so we can assess the exposure.
- Do not degrade the service. A proof of concept does not require volume.
- Give us a reasonable opportunity to remediate before disclosing publicly. Ninety days is our expectation, and we will discuss a shorter period where an issue is being actively exploited.
- Do not use a finding to extract payment. We do not operate a bug bounty, and we will not respond to a report framed as a demand.
05
What we commit to
- We will acknowledge your report and tell you whether we consider it in scope.
- We will investigate properly and keep you informed of progress at reasonable intervals.
- We will tell you when it is fixed, and what the fix was.
- We will credit you publicly if you would like that, and respect a preference for anonymity if you would not.
- We will not pursue legal action against anyone acting in good faith within this policy, and we will treat a report made in good faith as authorised access for that purpose.
We do not offer monetary rewards. That is a resourcing position, not a comment on the value of the work, and we would rather say so plainly than imply a bounty we do not operate.
06
If you have found something in a website we analysed
IXSEO performs passive analysis and does not test for weaknesses in the websites it examines. If you have independently discovered an issue in a third-party website, it should be reported to that organisation under its own disclosure process. We cannot pass it on, and we would not be an appropriate intermediary.
Related documents
Questions about this document can be raised through the contact page. Nothing here is intended to restrict rights you hold under applicable law.