Legal CentreDocument
Vulnerability Disclosure Policy
In scope
#The following properties operated by Prodia Systems Limited are in scope:
- the marketing website at
verinex.dev; - the Verinex Console at
console.verinex.dev; - documented Verinex APIs to which the reporter has authorised access.
Out of scope
#The following are out of scope for this policy:
- third-party services or infrastructure not operated by Prodia Systems Limited;
- social-engineering, phishing or physical-security attacks against personnel or premises;
- denial-of-service and volumetric testing;
- reports based solely on best-practice recommendations without a demonstrable security impact;
- issues in software or services that Prodia Systems Limited does not control.
Prohibited testing
#You must not, and must not attempt to:
- access, modify, exfiltrate or destroy data belonging to any other person;
- degrade the availability or integrity of Verinex or any dependent service;
- use automated scanners that generate significant load, submit spam or interact with real users;
- pivot to systems outside the in-scope properties;
- publicly disclose a vulnerability before it has been resolved and disclosure has been coordinated with Prodia Systems Limited.
How to report
#Please send a detailed report — including a description of the issue, the affected endpoint, reproduction steps, expected and observed behaviour, and any supporting material — using the contact below. Encrypt sensitive material where feasible.
Operator
Prodia Systems Limited
Public brand: Verinex — https://verinex.dev
Registered office
Pending verification
Company number
Pending verification
VAT number
Pending verification
Vulnerability reports
Pending verification
Safe harbour
#Prodia Systems Limited will not pursue civil action or initiate a complaint to law enforcement against a reporter for good-faith security research conducted in accordance with this policy. This safe harbour does not authorise activity that violates the prohibitions above, third-party rights, or applicable law, and it does not bind third parties.
Coordination and public disclosure
#We ask reporters to allow a reasonable period for Prodia Systems Limited to triage and remediate before any public disclosure, and to coordinate the timing and content of any public communication with us.
No bounty
#Prodia Systems Limited does not currently operate a paid bug-bounty programme. High-quality reports may be acknowledged in a security acknowledgements list at our discretion and with the reporter's consent.