Our commitment
IMAGIX values the work of security researchers and anyone who helps us protect our systems, products, customers, and users. If you believe you have found a vulnerability, report it responsibly so we can investigate and correct it.
How to report
Send the report to security@imagix.tech with:
- the affected system, URL, or product;
- a clear description of the issue and its potential impact;
- steps to reproduce it;
- supporting evidence, such as screenshots or logs, with sensitive data removed;
- a safe way to contact you.
Do not include personal, clinical, confidential, or third-party data unless strictly necessary. Encrypt sensitive details whenever possible.
Safe-harbor expectations
Research conducted in good faith, within this policy, and without harming people or services will be treated as authorized security research. We ask that you:
- avoid privacy violations, data destruction, service disruption, and social engineering;
- use only accounts and data you own or are authorized to access;
- stop testing and notify us if you encounter sensitive data;
- allow reasonable time for investigation and remediation before public disclosure;
- comply with applicable law.
Out of scope
Automated scans without evidence of impact, denial-of-service tests, spam, physical attacks, social engineering, and reports based only on outdated software versions are out of scope.
What to expect
We aim to acknowledge reports within five business days, assess severity, keep the reporter informed when possible, and coordinate disclosure after remediation. Response times may vary according to complexity and risk.
Recognition
This policy does not create a reward program or a contractual obligation. Recognition may be offered at IMAGIX’s discretion, and the contributions we recognise are listed in the Hall of Fame.
Contact
For questions about this policy, or to report a vulnerability, write to security@imagix.tech.