Responsible Disclosure & Security Reporting
Helping Strengthen Security Through Responsible Collaboration
At Harbix, we recognise the value of responsible security research and encourage individuals who identify potential security concerns to report them through appropriate channels.
A structured reporting process helps potential issues be reviewed, assessed, and addressed responsibly while protecting customers and maintaining service integrity.
Our Approach to Security Reporting
When a potential security concern is reported, Harbix aims to:
- Review the information provided.
- Assess the potential impact.
- Investigate relevant findings.
- Take appropriate action where required.
- Improve security practices where opportunities are identified.
All security reports are handled with appropriate consideration for customer protection and operational security.
What Security Issues Can Be Reported?
Examples of security concerns that may be reported include:
- Potential vulnerabilities affecting Harbix services.
- Unexpected security behaviour.
- Possible weaknesses affecting confidentiality or integrity.
- Security concerns involving Harbix platforms or services.
Reports should focus on identifying security risks and should avoid accessing, changing, or exposing customer information.
Responsible Testing Principles
Individuals conducting security research should:
- Act in good faith.
- Avoid accessing information belonging to others.
- Avoid disrupting services.
- Avoid making changes to systems or data.
- Keep security findings confidential until an review has taken place.
Responsible testing helps protect businesses and customers.
Information To Include in a Report
To help our security team review a report effectively, please provide:
- Description of the security concern.
- Steps required to reproduce the issue.
- Affected service or area.
- Potential impact.
- Supporting evidence where appropriate.
- Contact information for follow-up.
Clear information helps accelerate assessment and investigation.
Security Review Process
Reported concerns may go through the following stages:
- Assessment: Reviewing the report and understanding the potential security impact.
- Investigation: Analysing the issue and determining appropriate next steps.
- Resolution: Applying appropriate measures where a valid security concern is confirmed.
- Improvement: Using relevant findings to strengthen security practices.
Protecting Customer Information
Security reporting must always respect customer privacy and system integrity. Researchers and reporters should not:
- Access customer data.
- Download confidential information.
- Modify accounts or transactions.
- Publicly disclose vulnerabilities before appropriate review.
Reporting a Security Concern
If you believe you have identified a security issue affecting Harbix services, please contact Harbix through the official security communication channel:
Email: [email protected]
Providing complete information helps our team review the concern efficiently.
