Skip to main content

Security & Assurance

Security information belongs to a product trust surface.

XPScerpto separates security posture, disclosure, public advisories and evidence from operational administration while preserving a clear path for technical review.

SourceBuildRuntime
XPScerptosecurity
EvidenceReplayVerify

Security model

Understand boundaries between implementation, runtime, evidence and public claims.

Disclosure

Report vulnerabilities through the dedicated controlled intake path.

Advisories

Published advisories remain distinct from internal investigation material.

Assurance

Public security claims remain limited by admitted verification and governance state.

Security sectionsDisclosure

Coordinated vulnerability disclosure

Report security issues directly and safely.

A focused channel for good-faith security research affecting systems owned and operated by XPScerpto.

01

Authorized scope

Test only the assets listed below and only to the minimum extent needed to demonstrate the issue.

02

Outside scope

  • Third-party services, networks, repositories, identity providers, mail providers or hosting systems not owned or expressly authorized by XPScerpto.
  • Social engineering, phishing, physical intrusion, credential stuffing, denial-of-service and destructive testing.
  • Automated scanning that degrades availability or accesses data beyond the minimum proof required.

03

Permitted research

  • Use non-destructive techniques and stop after establishing a reproducible proof.
  • Use accounts and data you own or are explicitly authorized to use.
  • Protect any data encountered and report it immediately without further access.

04

Do not

  • Do not perform denial-of-service, destructive testing, social engineering, phishing or credential attacks.
  • Do not test third-party infrastructure or services that XPScerpto does not control.
  • Do not exfiltrate, retain, modify or publish personal, confidential or security-restricted data.

05

Coordinated handling

  • Receipt confirms intake only; it does not validate the vulnerability.
  • The security team will scope, reproduce and triage the report before remediation.
  • Publication requires redaction, independent verification and explicit advisory approval.

06

Operational expectations

You will receive a reference and private follow-up code immediately. No unverified response deadline is promised. Updates appear in the secure status channel.

Report a vulnerability

Report a vulnerability