Coordinated vulnerability disclosure
Help us resolve security issues safely.
This policy authorizes good-faith research only against the explicitly listed in-scope asset and within the rules below.
Report privately
Email support@delx.ai with [SECURITY] in the subject. Include the affected URL, impact, reproduction steps and the smallest proof needed to establish the issue.
Only security.delx.ai is in scope for this policy. Other Delx domains, third-party services, people and infrastructure are excluded unless separately authorized in writing.
Safe harbor conditions
- Act in good faith and stop after confirming the minimum evidence.
- Do not access, modify, retain or disclose data that is not yours.
- Do not use denial of service, social engineering, phishing, physical testing or destructive techniques.
- Do not automate high-volume requests or degrade availability.
- Give us a reasonable opportunity to investigate and remediate before public disclosure.
- Comply with applicable law and any written scope limitations we provide.
What to expect
We will acknowledge valid reports when operationally possible, investigate proportionately and communicate material status changes. This is a vulnerability disclosure channel, not a paid bug-bounty program, and no reward is promised.
Research outside these conditions is not authorized by this policy. If you are uncertain whether a technique is safe, ask before testing it.