At Oxyfi, security is a core part of how we build and operate our products and services. We welcome responsible reports from security researchers, customers, partners, and members of the security community who believe they have identified a security vulnerability in an Oxyfi system.
This policy explains how to report a potential vulnerability, what we ask of researchers, and what you can expect from us.
If you believe you have discovered a security vulnerability affecting Oxyfi, please contact us at:
Email: security@oxyfi.com
Please include as much detail as possible to help us investigate efficiently:
Please do not include sensitive personal data or confidential third-party information unless it is strictly necessary to demonstrate the issue.
To protect sensitive vulnerability information, Oxyfi supports encrypted vulnerability submissions using OpenPGP.
Email: security@oxyfi.com
Key ID: B30F3E84B99F05F8
Fingerprint: F025 9485 ADBA 29D3 6514 D6F2 B30F 3E84 B99F 05F8
Download Public Key: https://oxyfi.com/secure/pgp-pub-2026-06-25.txt
Researchers are encouraged to encrypt vulnerability reports that contain sensitive technical details, proof-of-concept code, exploit information, or other security-related information.
Before using the key, please verify that the fingerprint matches the fingerprint published on this page.
Oxyfi may periodically rotate or replace its OpenPGP key. The key and fingerprint published on this page should always be considered authoritative.
This policy applies to digital assets owned, operated, or maintained by Oxyfi, including:
If you are unsure whether a system is in scope, please contact us before testing.
The following activities are not permitted under this policy:
Oxyfi reserves the right to determine whether a report is in scope.
When conducting security research, we ask that you:
When we receive a vulnerability report, we aim to:
Not every report will result in a confirmed vulnerability, but we review all good-faith submissions.
Oxyfi supports good-faith security research and will not pursue legal action against individuals who discover and report vulnerabilities in accordance with this policy.
Research conducted under this policy is considered authorized, provided that you:
If a third party initiates legal action against you for activities conducted in accordance with this policy, Oxyfi will take reasonable steps to clarify that your research was authorized under this policy.
Oxyfi supports coordinated vulnerability disclosure.
We ask that you provide Oxyfi with a reasonable amount of time to investigate, remediate, and communicate about any confirmed vulnerability before publicly disclosing details.
Where appropriate, we may work with researchers on a mutually agreed disclosure timeline.
We appreciate the efforts of responsible security researchers.
Subject to legal, privacy, confidentiality, and business considerations, Oxyfi may acknowledge researchers who responsibly disclose valid vulnerabilities.
Oxyfi does not currently operate a bug bounty or monetary reward program unless explicitly stated otherwise.
Information submitted under this policy will be used solely to investigate, validate, remediate, and communicate about reported security issues.
Personal information will be handled in accordance with applicable data protection laws and Oxyfi’s Privacy Policy.
For vulnerability reports and security-related concerns, please contact:
Email: security@oxyfi.com
Thank you for helping keep Oxyfi, our customers, and our partners secure.