No monetary bounty or prize
Protexct does not offer a monetary bug bounty, monetary prize, payment, or other financial reward for submitting a vulnerability or bug report. Submitting a report does not create an entitlement to compensation.
1. How to report a vulnerability
Email security@protexct.com with the subject line “Security report”. Please include a clear description, affected URL or component, reproduction steps or proof of concept, security impact, and your preferred contact details.
If a report involves customer data or an active incident, do not include sensitive data in the email. Describe the issue and we will provide a safer channel when appropriate.
2. Responsible testing guidelines
Test only systems you own or are explicitly authorized to test. Avoid accessing, changing, or deleting data; avoid service degradation, denial-of-service activity, spam, social engineering, credential attacks, and automated high-volume scanning.
Stop testing and contact us promptly if you encounter customer information, secrets, or evidence of an active compromise. Minimize data access and securely delete anything obtained unintentionally.
3. What happens after a report
We will review the report, may ask for additional details, and will work to validate and remediate confirmed issues. We may acknowledge a report publicly only with your permission and without exposing sensitive details.
We do not promise a response time, a particular outcome, or a public credit. Reports are evaluated based on technical impact, exploitability, scope, and whether the issue was previously known.
4. Security questions
For security architecture, disclosure, or incident questions, contact security@protexct.com. For general support, contact support@protexct.com.