← All legal documents

Vulnerability Disclosure Policy

Version 1.0 · effective 14/07/2026

CapIX welcomes good-faith research that protects Customers, Providers and the decentralised network. Report privately to hello@capix.network with "Security" in the subject.

Scope and safe harbour

In scope are CapIX-owned production domains and APIs, current CapIX IDE and CapIX Code releases, routing and control-plane components, and CapIX smart contracts. Third-party Provider infrastructure is out of scope unless explicitly identified.

Use only accounts and nodes you own or have written permission to test. Minimise access and stop after proving impact. Do not retain, alter or disclose personal data or Customer Content; disrupt service; social-engineer; phish; extort; spam; perform denial of service; access treasury or real funds; or exploit third parties. Report promptly, redact credentials and keep details confidential until coordinated disclosure. CapIX will treat research following this policy as authorised and will not initiate legal action for accidental good-faith violations, although this cannot bind third parties or excuse unlawful conduct.

Report and response

Include affected asset and version, reproduction steps, impact, redacted evidence and your contact or credit preference. Never send live private keys or Customer datasets. CapIX targets acknowledgement within two business days, triage within five, status updates at least every ten, and coordinated disclosure within 90 days, adjusted for active exploitation or ecosystem dependencies. Rewards, if offered, require prior eligibility confirmation. Duplicate, theoretical, self-XSS, unsupported-version and missing-header reports without demonstrated impact may be ineligible. Report leaked credentials immediately and do not use them.

Publication fingerprint

SHA-256 f6f9c2b18ade2617c03716fda19a3d9c0a77acac077601cfa860ef97691160cd