Home/Compliance/Vulnerability Disclosure Policy

Vulnerability Disclosure Policy

Last updated August 2026· Applies to all Fix24.cloud customers

Fix24.cloud ("Fix24", "we", "us") values the work of independent security researchers in helping us keep our platform and customers safe. This policy explains how to report a suspected security vulnerability to us responsibly, and what you can expect from us in return.

1.Scope

This policy applies to fix24.cloud and its client portal, and Fix24-operated infrastructure and services. It does not authorize testing of third-party services, upstream data center providers, or systems and applications hosted by our customers on their own servers — those remain the responsibility of the respective owner.

2.Reporting a Vulnerability

If you believe you have discovered a security vulnerability, please report it to support@fix24.cloudwith the subject line "Security Vulnerability Report", including:

  • A clear description of the vulnerability and its potential impact;
  • Steps to reproduce, including affected URLs, endpoints, or systems;
  • Proof-of-concept code or screenshots, if available; and
  • Your contact details, so we can follow up with questions or updates.

3.Responsible Testing Guidelines

While researching, please:

  • Avoid accessing, modifying, or deleting data that does not belong to you;
  • Avoid degrading the performance or availability of our systems, including automated scanning that generates significant load;
  • Do not use findings to access other customers' accounts or data beyond what is minimally necessary to demonstrate the issue;
  • Do not publicly disclose a vulnerability until we have confirmed a fix or 90 days have passed since your report, whichever is sooner, unless we agree to a different timeline; and
  • Avoid social engineering, physical attacks, or spam against our staff or customers.

Research conducted in good faith and consistent with this policy will not result in legal action from Fix24, and we will not report you to law enforcement for such research.

4.Our Commitment

We will acknowledge receipt of your report within the timeframes set out in our SLA for critical/high severity issues, investigate promptly, keep you reasonably informed of our progress, and notify you once the issue is resolved. We do not currently operate a paid bug bounty program, but we are happy to publicly credit researchers who wish to be acknowledged, with their permission.

5.Out of Scope

Reports of theoretical vulnerabilities without a working proof of concept, vulnerabilities requiring physical access to a device, social engineering of Fix24 staff, or issues in third-party software not controlled by Fix24 are generally considered lower priority or out of scope, though we welcome all reports for review.

6.Changes to This Policy

We may update this policy from time to time. Material changes will be posted here with an updated date.

7.Contact Us

Report vulnerabilities to support@fix24.cloud. Fix24.cloud, Datamation Group, Guwahati, Assam, India.

Questions about this document?

Our team can walk you through any part of this policy.

Contact Us