Skip to content
  • Home
  • Projects
  • About
Get in touch

Legal

Security and Responsible Disclosure

Last updated: 13 September 2026 Applies to: techfxlabs.com

On this page

How to report What to include What we commit to Scope Out of scope Safe harbour Bug bounty Machine-readable policy

We welcome reports from security researchers acting in good faith. If you think you have found a vulnerability in this website or another TechFXLabs service, please tell us so we can fix it.

How to report

Email security@techfxlabs.com. Please do not open a public issue, post the details on social media, or otherwise disclose the problem before we have had a reasonable chance to address it.

If you would like to encrypt your report, say so in a first message and we will arrange a key exchange. A machine-readable copy of this policy is published at /.well-known/security.txt.

What to include

  • A clear description of the issue and its potential impact.
  • Steps to reproduce it, with the exact URL or endpoint involved.
  • Any proof-of-concept, screenshots, or request and response pairs, kept minimal and free of other people's data.
  • How you would like to be credited, if at all.
  • A contact address we can reply to.

What we commit to

  • Acknowledge your report, normally within five working days.
  • Keep you updated on our assessment and on the fix.
  • Not pursue or support legal action against you for the report itself.
  • Credit you for the finding if you want to be credited, and keep you anonymous if you prefer.
  • Treat your report as confidential, and share it only with the people who need it to resolve the issue.

Scope

In scope are the systems we operate and control, including techfxlabs.com and its subdomains, our DNS and hosting configuration, and any product we run under our own domain.

Out of scope

Please do not test, and do not report, the following:

  • Any third-party website or service we merely link to.
  • Findings that require physical access to a device, or that rely on a compromised device, browser extension, or network the visitor controls.
  • Automated scanner output with no demonstrated impact, missing security headers without a concrete exploit, and best-practice suggestions with no vulnerability.
  • Denial-of-service testing, load testing, social engineering, or phishing against our staff.
  • Reports about outdated software versions with no proven impact.

This is a static informational website. It has no login, no user accounts, and stores no visitor personal data, so classes of issue such as authentication or session handling do not apply here.

Safe harbour

If you act in good faith, stay within the scope above, avoid privacy violations and service disruption, and give us a reasonable opportunity to fix the issue before disclosing it, we will not take legal action against you for your research. We will treat your activity as authorised, and we will make this clear to any third party that asks.

This safe harbour does not cover anything outside that scope, and it does not bind third parties.

Bug bounty

We do not currently operate a paid bug bounty programme. We are grateful for reports and we will credit them, but we cannot offer financial rewards at this time.

Machine-readable policy

Our disclosure policy is also published in the security.txt format at /.well-known/security.txt.

TechFXLabs

A software studio building focused products. Home of Life of a Pet.

Site

  • Home
  • Projects
  • About

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Company Information
  • Accessibility
  • Security

Contact

  • hello@techfxlabs.com
  • security@techfxlabs.com

© 2026 TechFXLabs. All rights reserved.

Company information · Privacy · Terms