Responsible Disclosure Policy

We consider the security of our systems a top priority. No matter how much effort we put into it, vulnerabilities can still exist. If you discover one, we would like to know so we can address it as quickly as possible, and we ask for your help in protecting our clients and our systems.

Scope

This policy covers vulnerabilities in systems and services operated by Axoniq. If you believe you have found an issue in a product or service provided to us by a third party, please report it to that vendor directly. You are welcome to let us know as well, so we can follow up with our suppliers where appropriate.

How to report

Email your findings to security-disclosure@axoniq.io and include:

  • A clear description of the vulnerability, and specifically which system or service it affects (for example the Platform, Console, or Support site). Reports that do not identify the affected system cannot be actioned.

  • Steps to reproduce the issue. In most cases the IP address or URL of the affected system plus a description is enough. More complex vulnerabilities may need further explanation.

  • Any logs, screenshots, or other evidence that helps our team understand and confirm the problem.

  • Optionally, a suggested mitigation or fix. Please note we may not be able to follow every suggestion.

What we ask of you

  • Do not exploit the issue beyond what is necessary to demonstrate it, for example by accessing more data than needed, or by deleting or modifying data that is not yours.

  • Do not disclose the issue to others until it has been resolved.

  • Do not use physical attacks, social engineering, distributed denial of service, spam, or attacks against third-party applications.

  • Avoid any action that could disrupt our services or affect other users.

What we promise

  • We will acknowledge your report within three business days with an initial assessment and, where possible, an expected resolution timeline.

  • We will handle your report confidentially and will not share your personal details with third parties without your permission.

  • We will keep you informed of our progress.

  • With your consent, we are happy to credit you as the discoverer once the issue is resolved, and we would welcome coordinating with you on any public disclosure.

Recognition and rewards

We are grateful for every good-faith report and will always acknowledge your contribution. For findings that we are able to verify as genuine, exploitable security vulnerabilities that were not already known to us, we may also offer a reward as a token of our appreciation. Where a reward is given, the amount is determined at our discretion based on the severity of the issue and the quality of the report.

Reports that describe configuration hardening opportunities, compliance or best-practice recommendations, or the output of automated scanners without a demonstrated, exploitable impact are valuable to us and always welcome, but they fall outside the scope of our rewards.

Safe Harbor

We believe responsible security researchers are invaluable in helping us improve. If you act in good faith and follow this policy, we will not pursue legal action against you for discovering and reporting a vulnerability.

Thank you

We appreciate your efforts to help keep our systems and our users secure. Your contributions help us maintain a strong security posture and a safer experience for everyone.