Vulnerability Disclosure
We take security seriously and appreciate the work of security researchers in helping us keep PriFox and our users safe. Last updated: July 15, 2026.
1. Reporting a vulnerability
We take security seriously and appreciate the work of security researchers in helping us keep PriFox and our users safe. If you believe you have discovered a security vulnerability, please report it to us responsibly.
We ask that you do not publicly disclose the vulnerability until we have had a reasonable opportunity to address it. We will acknowledge receipt of your report within 48 hours and aim to provide a resolution timeline within 5 business days.
2. PGP key
If you prefer to encrypt your vulnerability report, you can use our public PGP key below.
-----BEGIN PGP PUBLIC KEY BLOCK----- xsFNBGdPnxQBEACz3Z7tXz3g0g0g0g0g0g0g0g0g0g0g0g0g0g0g0g0g0g0g0g0 [Example PGP key fingerprint: 0xA1B2C3D4E5F6...] Contact security@prifox.com for the full public key. -----END PGP PUBLIC KEY BLOCK-----
3. Scope
The following domains and services are in scope for vulnerability reports:
- prifox.com and all subdomains
- Our API endpoints (api.prifox.com)
- Our platform dashboard and authenticated services
4. Safe harbour
We will not take legal action against researchers who act in good faith to discover and report vulnerabilities, provided they:
- Do not access, modify, or delete data belonging to other users.
- Do not disrupt our services or degrade performance.
- Do not publicly disclose the vulnerability before we have addressed it.
- Provide sufficient detail to allow us to reproduce and verify the issue.
5. Response timeline
- Acknowledgement: Within 48 hours of receipt.
- Initial assessment: Within 5 business days.
- Resolution target: Critical vulnerabilities within 14 days; high severity within 30 days.
- Public disclosure: After mutual agreement and patch deployment.
6. Out-of-scope testing
The following activities are out of scope and not authorised:
- Social engineering or phishing attacks against PriFox staff or users.
- Physical security testing of our offices or infrastructure.
- Denial-of-service attacks that impact service availability.
- Testing on third-party services not explicitly listed in scope.
7. Our commitments
We are committed to maintaining the highest standards of security for our platform. We value the security research community and will work collaboratively with researchers to resolve identified vulnerabilities promptly and transparently. All reports are treated with confidentiality.