Vulnerability Disclosure Policy

At Oxyfi, security is a core part of how we build and operate our products and services. We welcome responsible reports from security researchers, customers, partners, and members of the security community who believe they have identified a security vulnerability in an Oxyfi system.

This policy explains how to report a potential vulnerability, what we ask of researchers, and what you can expect from us.

Report a Vulnerability

If you believe you have discovered a security vulnerability affecting Oxyfi, please contact us at:

Email: security@oxyfi.com

Please include as much detail as possible to help us investigate efficiently:

  • A description of the vulnerability
  • The affected product, service, URL, API, or system
  • Steps to reproduce the issue
  • Screenshots, logs, proof-of-concept code, or other supporting material
  • Potential impact
  • Your contact details, if you would like us to follow up

Please do not include sensitive personal data or confidential third-party information unless it is strictly necessary to demonstrate the issue.

Secure Communications

To protect sensitive vulnerability information, Oxyfi supports encrypted vulnerability submissions using OpenPGP.

Security Contact

Email: security@oxyfi.com

OpenPGP Public Key

Key ID: B30F3E84B99F05F8

Fingerprint: F025 9485 ADBA 29D3 6514 D6F2 B30F 3E84 B99F 05F8

Download Public Key: https://oxyfi.com/secure/pgp-pub-2026-06-25.txt

Researchers are encouraged to encrypt vulnerability reports that contain sensitive technical details, proof-of-concept code, exploit information, or other security-related information.

Key Verification

Before using the key, please verify that the fingerprint matches the fingerprint published on this page.

Key Updates

Oxyfi may periodically rotate or replace its OpenPGP key. The key and fingerprint published on this page should always be considered authoritative.

Scope

This policy applies to digital assets owned, operated, or maintained by Oxyfi, including:

  • Oxyfi websites
  • Oxyfi web applications
  • Oxyfi APIs
  • Oxyfi cloud services
  • Oxyfi-developed software and services
  • Oxyfi-managed infrastructure

If you are unsure whether a system is in scope, please contact us before testing.

Out of Scope

The following activities are not permitted under this policy:

  • Social engineering, phishing, or attempts to deceive Oxyfi employees, customers, or partners
  • Physical security testing
  • Denial-of-service (DoS/DDoS) testing
  • Spam, malware, or automated attacks that may affect service availability
  • Accessing, modifying, deleting, or exfiltrating data beyond what is necessary to demonstrate a vulnerability
  • Testing third-party systems or services not controlled by Oxyfi
  • Public disclosure before Oxyfi has had a reasonable opportunity to investigate and address the issue

Oxyfi reserves the right to determine whether a report is in scope.

Responsible Research Guidelines

When conducting security research, we ask that you:

  • Act in good faith
  • Avoid privacy violations and service disruption
  • Access only the minimum information necessary to prove the issue
  • Stop testing immediately if you encounter sensitive data
  • Report the issue to Oxyfi as soon as possible
  • Keep information about the vulnerability confidential until it has been resolved or coordinated disclosure has been agreed
  • Do not exploit the vulnerability beyond what is necessary to confirm its existence

What You Can Expect From Us

When we receive a vulnerability report, we aim to:

  • Acknowledge receipt within five (5) business days
  • Review and triage the report
  • Investigate and validate the issue
  • Keep you informed of progress where appropriate
  • Prioritize remediation based on severity, exploitability, and potential impact
  • Coordinate disclosure when appropriate

Not every report will result in a confirmed vulnerability, but we review all good-faith submissions.

Safe Harbor

Oxyfi supports good-faith security research and will not pursue legal action against individuals who discover and report vulnerabilities in accordance with this policy.

Research conducted under this policy is considered authorized, provided that you:

  • Follow the rules and scope described in this policy
  • Avoid harm to Oxyfi, our customers, partners, and users
  • Do not access, modify, retain, or disclose data except as necessary to demonstrate the vulnerability
  • Report the vulnerability promptly
  • Do not publicly disclose the issue before coordinated disclosure has been agreed

If a third party initiates legal action against you for activities conducted in accordance with this policy, Oxyfi will take reasonable steps to clarify that your research was authorized under this policy.

Coordinated Disclosure

Oxyfi supports coordinated vulnerability disclosure.

We ask that you provide Oxyfi with a reasonable amount of time to investigate, remediate, and communicate about any confirmed vulnerability before publicly disclosing details.

Where appropriate, we may work with researchers on a mutually agreed disclosure timeline.

Recognition

We appreciate the efforts of responsible security researchers.

Subject to legal, privacy, confidentiality, and business considerations, Oxyfi may acknowledge researchers who responsibly disclose valid vulnerabilities.

Oxyfi does not currently operate a bug bounty or monetary reward program unless explicitly stated otherwise.

Privacy

Information submitted under this policy will be used solely to investigate, validate, remediate, and communicate about reported security issues.

Personal information will be handled in accordance with applicable data protection laws and Oxyfi’s Privacy Policy.

Contact

For vulnerability reports and security-related concerns, please contact:

Email: security@oxyfi.com

Thank you for helping keep Oxyfi, our customers, and our partners secure.