Security & Vulnerability Reporting
Last updated 19 August 2026
We take security seriously across the websites, bots and automations we build. This page explains how to reach us and what to expect.
1. Reporting a vulnerability
Email security@relaxs.dev with a description of the issue, the affected URL or system, and reproduction steps. Please give us a reasonable window to respond before public disclosure.
2. Testing guidelines
- Only test systems you own or have written permission to test.
- No denial-of-service, spam or social engineering of staff or users.
- Do not access, modify or exfiltrate data that is not yours; stop as soon as you confirm a flaw.
3. Our response
We aim to acknowledge reports promptly, keep you updated on triage, and credit reporters who ask for it once a fix ships. We do not currently run a paid bounty programme.
4. Practices we follow
- Encryption in transit for all public endpoints.
- Least-privilege credentials and secrets kept out of source control.
- Dependency updates and review of security-relevant changes before release.
- Access to client systems limited to the people working on the engagement.
Specific controls, certifications or contractual security commitments for an engagement are agreed in writing — nothing on this page should be read as a certification claim.
This document is provided for transparency and is not legal advice. If you need contract terms tailored to your jurisdiction, have a qualified lawyer review it.