Last updated: July 30, 2026

1. Introduction

Xponzy Tech LLC values the work of security researchers who help keep the internet safe. If you believe you have found a vulnerability in our systems, we want to hear about it, and this policy explains how to report it, what we ask of you, and what you can expect from us in return.

2. Scope

This policy covers systems operated by Xponzy Tech LLC, namely:

  • The website xponzy.com and its subdomains;
  • Our client portal and support systems hosted under those domains.

Out of scope: systems operated by third parties, even when they integrate with our services. This includes payment processing by Stripe and PayPal, domain registries and registrars, and third-party products such as Google Workspace, which is operated by Google. Please report vulnerabilities in third-party products directly to the relevant vendor through its own disclosure channel. Client websites hosted on our infrastructure belong to our clients and are out of scope unless the issue lies in the underlying platform we operate.

3. How to Report

Submit your report through our support portal at https://xponzy.com/submitticket.php, marking it clearly as a security report. Please include:

  • A description of the vulnerability and its potential impact;
  • Steps to reproduce, including URLs, parameters, and any required conditions;
  • The date and time of your testing and the IP address you tested from, if available;
  • Any proof-of-concept material, limited to the minimum needed to demonstrate the issue.

Reports in English or Spanish are welcome. If you prefer not to create an account, you may also reach us through the contact form at https://xponzy.com/contact.php.

4. Rules of Engagement

To keep research safe for everyone, you must not:

  • Perform denial-of-service testing or any activity that degrades service for our clients;
  • Access, copy, modify, or delete data that does not belong to you; if you encounter someone else's data, stop, do not save it, and report immediately;
  • Use social engineering, phishing, or physical intrusion against Xponzy, its personnel, or its clients;
  • Run automated scanners at high intensity against production systems;
  • Pivot from a discovered vulnerability to further exploitation beyond what is needed to demonstrate the finding;
  • Publicly disclose the issue before we have had a reasonable opportunity to fix it.

5. Safe Harbor

We will not pursue legal action or law enforcement referral against researchers who act in good faith and within this policy. Specifically, research conducted in accordance with this policy is considered authorized under applicable anti-hacking and anti-circumvention laws to the extent we can authorize it, and we waive claims we might otherwise have for such conduct. This safe harbor does not extend to actions that exceed this policy, affect third parties, or involve the compromise of data belonging to others. If you are unsure whether a planned test is within scope, ask us first.

6. What You Can Expect from Us

  • Acknowledgment of your report, normally within five business days;
  • An initial assessment and, where warranted, a remediation plan with an estimated timeline;
  • Updates on progress until the issue is resolved;
  • Credit for the finding, if you wish, once a fix is deployed and coordinated disclosure is agreed.

7. Rewards

We do not currently operate a paid bug bounty program, and no monetary reward is offered for reports. We are genuinely grateful for responsible reports and are happy to publicly acknowledge researchers who agree to be named. If we introduce a bounty program in the future, it will be announced on this page with its own rules.

8. Questions

Questions about this policy can be sent through our contact form at https://xponzy.com/contact.php.