Xtremepush · Security

Vulnerability Disclosure Policy

How to report a security issue in something we run, what happens after you send it, and the ground rules that keep the process safe for you and for us.

.well-known/security.txt
Contact: mailto:infosec@xtremepush.com
Expires: 2027-12-31T00:00:00.000Z
Preferred-Languages: en
Policy: https://www.xtremepush.com/security/vulnerability-disclosure-policy

Xtremepush operates the customer engagement platform that our customers — including a number of regulated financial institutions — depend on to reach their own users safely. Keeping it secure is partly our job, and partly the job of independent researchers who take the time to look closely and tell us what they find.

If you believe you've discovered a security vulnerability in a system we own or operate, we want to hear from you. This policy sets out how to report it, what you can expect from us in return, and the rules that protect good-faith research.

Scope

What this policy covers

In scope
  • xtremepush.com and its subdomains
  • The Xtremepush web application, dashboard, and admin console
  • Publicly reachable Xtremepush APIs
  • Official Xtremepush web and mobile SDKs
Out of scope
  • Systems, products, or domains not owned or operated by Xtremepush, including third-party integrations
  • Denial-of-service, resource-exhaustion, or high-volume automated scanning
  • Social engineering or phishing aimed at our staff, contractors, or customers
  • Physical access attempts against our offices or infrastructure
  • Issues that need a jailbroken device or physical access to someone else's device
  • Reports limited to missing headers, cookie flags, or version banners with no demonstrated impact
If you're not sure whether something is in scope, report it anyway. We'd rather hear about a borderline finding than have you skip it.

How to report

Send us what you found

Email infosec@xtremepush.com with as much of the following as you can:

  • A description of the issue and why it matters
  • Steps to reproduce it, or a proof of concept
  • The affected URL, endpoint, or component
  • Any tools you used

Please use test accounts or synthetic data rather than real customer data when demonstrating an issue. We don't currently publish a PGP key — if your report involves sensitive information, say so in your first email and we'll agree a secure way to share the rest.

What to expect

Our process, step by step

  1. 1

    Acknowledgement

    We confirm we've received your report, typically within 3 business days.

  2. 2

    Triage

    We validate and assess severity, typically within 10 business days, and may ask follow-up questions.

  3. 3

    Investigation & fix

    We work on a remediation. Complex issues take longer than simple ones — we'll tell you where things stand.

  4. 4

    Updates

    We check in with you at least every two weeks until the issue is resolved.

  5. 5

    Resolution

    We let you know once it's fixed and agree with you on disclosure timing.

These are targets, not guarantees — actual timelines vary with severity and complexity.

Coordinated disclosure

Please keep details of a reported issue private until we've had a reasonable opportunity to fix it — normally up to 90 days from your report, or another timeframe we agree with you directly. We ask that you don't disclose publicly before then.

Safe harbor

Good-faith research is welcome here

We consider security research carried out under this policy to be authorized. If you make a good-faith effort to follow it, we won't pursue legal action against you for that research, and we'll treat your conduct as authorized under any relevant computer-misuse law. That's conditional on you:

  • only interacting with accounts, data, and systems you own or have explicit permission to test
  • avoiding privacy violations, service disruption, and destruction of data
  • giving us a reasonable opportunity to investigate and fix the issue before any public disclosure
  • stopping immediately and telling us if you encounter data that isn't yours — for example, another customer's records

If a third party threatens or brings legal action against you for activity that was consistent with this policy, we will make clear that your actions were authorized.

Recognition & rewards

Thanks, without a price tag — for now

No paid bounty programme is currently open

Xtremepush does not currently run a financial reward or bug bounty programme, and no monetary payment is offered for reports made under this policy.

That doesn't mean the work goes unrecognized. For confirmed, previously unknown issues:

  • We'll thank you directly and tell you how — or whether — we're addressing what you found.
  • With your permission, we're happy to credit you publicly as the researcher who reported it.
  • If we launch a paid bug bounty programme in future, we may invite researchers who've submitted verified reports under this policy to take part.

We'll always be straightforward about where things stand — we won't imply a reward is coming and then leave you without one.

Contact

Get in touch

Email: infosec@xtremepush.com
Preferred language: English

This address is for security reports covered by this policy. For account or product support, please use standard Xtremepush support channels instead.