Responsible Disclosure Policy
Last updated 24 July 2026 · Version 0.1 (draft)
We welcome reports from security researchers. If you believe you have found a vulnerability in a CRCX system, this policy explains how to tell us and what you can expect in return.
| Name | Function | Location | Data processed |
|---|
Scope
This policy covers systems that CRCX operates, including the marketing site, the app, and the client platform. Third party services we use are covered by their own programmes.
How to report
Send your report to {{TO CONFIRM: security@crcx.eu}}. Please give us reasonable time to investigate and fix an issue before you disclose it publicly.
Safe harbour
We will not pursue or support legal action against researchers who act in good faith under this policy, who avoid harm to people and data, and who do not break the law. If in doubt, contact us before you act.
What to include
- A clear description of the issue and where you found it.
- Steps to reproduce, with any proof of concept.
- The potential impact as you see it.
- How we can reach you for follow up.
What to expect
We aim to acknowledge a report within {{TO CONFIRM: acknowledgement time, e.g. 3 business days}} and to keep you updated as we work through it. Target timelines for triage and fixes: {{TO CONFIRM: response and remediation targets}}.
Out of scope
- Denial of service, spam, or social engineering of our staff or users.
- Reports from automated scanners with no demonstrated impact.
- Issues that require physical access to a device or a fully compromised account.
- {{TO CONFIRM: any further out of scope items}}
Encryption
If you would like to encrypt your report, use our PGP key: {{TO CONFIRM: PGP key or fingerprint, or state that none is offered}}.
Machine readable contact
Our security contact is also published at https://crcx.eu/.well-known/security.txt, following the security.txt standard.