SecureLynx Vulnerability Disclosure

Found something? Tell us.

Last updated: August 2026

If you have found a security problem in something SecureLynx runs, we want to hear about it. This page tells you where to send it, what is in scope, and what we commit to in return. Good-faith research within the scope below is authorized, and we will not pursue legal action over it.

How to report

Email security@securelynx.it. There is no form and no account required. Tell us what you found, where you found it, and enough detail for us to reproduce it. Screenshots, requests, and steps help. English is preferred.

If you need to send something sensitive over an encrypted channel, say so in your first message and we will arrange one.

Authorization and safe harbour

Our Terms of Use ask visitors not to attempt to reach non-public areas, accounts, or systems. This policy is the exception to that clause. Security research carried out in good faith and within the scope below is authorized, and we will not pursue legal action against you, file a complaint, or ask anyone else to, on account of it.

If a third party takes action against you over research we authorized here, tell us and we will confirm in writing that it was authorized.

In scope

The SecureLynx website at securelynx.it, and the SecureLynx Compliance Portal at portal.securelynx.it.

Our support helpdesk runs on third-party software we do not operate. Issues in the platform itself belong to that vendor, though we would still like to know.

Out of scope

Client environments are never in scope. We manage networks, devices, and accounts that belong to our clients, not to us, and we cannot authorize anyone to test them. If you believe you have noticed something about a client environment, describe it to us in words. Do not go looking.

Also out of scope: services we use but do not operate, including our host, our mail provider, and our analytics provider; social engineering of our staff, our clients, or our vendors; physical access attempts; and any form of denial of service, load testing, or stress testing.

Scanner output on its own is not a finding. A missing header, an absent DNS record, a TLS configuration opinion, or a grade from an automated tool is welcome as information, but we will treat it as a report only if you can show what an attacker could actually do with it.

What we ask of you

Stop at proof. Do not access, modify, download, or keep data that is not yours, and do not degrade or interrupt service for anyone else. If you encounter personal data or client information, stop immediately and tell us what you saw rather than collecting it.

Give us a reasonable window to fix what you found before publishing. Ninety days is our suggestion, and we will tell you promptly if we expect to need longer.

What we will do

We will acknowledge your report within three business days, tell you whether we can reproduce it and whether we intend to fix it, and keep you informed until it is closed. If we decide not to act on something, we will tell you that too, and why.

Recognition

We do not run a paid bug bounty. If you would like credit for a valid report, ask and we will name you when the issue is resolved. If you would rather stay anonymous, that is fine as well.

Contact

Security reports: security@securelynx.it. For anything that is not a security report, contact SecureLynx in the usual way.