Skip to main content

Legal

Responsible Disclosure Policy

Last updated: July 16, 2026

NarrowGateX values the work of security researchers who help us protect our customers and platform. This policy explains how to report a potential vulnerability and the boundaries for good-faith security research.

1. Reporting a Vulnerability

Email reports to security@narrowgatex.com. Please include:

  • The affected URL, feature, or service
  • Clear reproduction steps and supporting evidence
  • The potential impact and any conditions required to reproduce it
  • Your preferred name for acknowledgment, if any

Do not include customer data, credentials, or unnecessary sensitive information in the report.

2. Good-Faith Research

Keep testing non-destructive and limited to accounts, systems, and data you own or are explicitly authorized to use. Public-page review, response-header inspection, and limited validation necessary to demonstrate a vulnerability are generally appropriate when they do not affect other users or service availability.

Stop testing and report the issue promptly if you encounter another person’s data, gain unintended elevated access, or could cause disruption.

3. Prohibited Activity

This policy does not authorize:

  • Accessing, changing, downloading, retaining, or disclosing another customer’s data
  • Phishing, social engineering, credential attacks, or testing against NarrowGateX employees or customers
  • Denial of service, excessive automated traffic, destructive testing, malware, or persistence
  • Physical attacks, third-party service testing, privacy violations, or disruption of production systems
  • Public disclosure before NarrowGateX has had a reasonable opportunity to investigate and remediate the issue

4. Our Response

We will make a reasonable effort to acknowledge credible reports, investigate them, and keep the reporter informed of material remediation. Response and remediation times depend on the issue’s severity, complexity, and affected systems.

We ask that reporters preserve confidentiality while we investigate and coordinate any disclosure with us in advance.

Recognition and Compensation

NarrowGateX does not currently operate a public bug-bounty program. We may acknowledge helpful reports at our discretion, including private thanks or public recognition with the reporter’s permission. Submitting a report does not create an entitlement to payment, compensation, or any other reward.

5. Good-Faith Commitment

When research follows this policy, is intended to improve security, avoids harm, and is reported promptly, NarrowGateX will treat it as good-faith activity. This policy does not provide permission to violate applicable law, access third-party data, or test systems that NarrowGateX does not own.

6. Contact

NarrowGateX Security

Email: security@narrowgatex.com