Responsible disclosure
If you believe you’ve found a security issue in XenonCloud’s infrastructure, control panel,
or public-facing services, we want to hear about it. We ask that you:
- Report the issue privately and promptly.
- Give us reasonable time to investigate and remediate before public disclosure.
- Avoid accessing, modifying, or destroying data that does not belong to you.
Please include detailed steps to reproduce, any proof-of-concept code, and affected systems or endpoints.
How to contact our security team
To report a potential vulnerability or security concern, contact us via the
contact page with “Security” in the subject line.
For highly sensitive reports, we can arrange an encrypted communication channel
after initial contact.
Please do not perform denial-of-service testing or any activity that disrupts
customer workloads without explicit written permission.