NarrowGateX values the work of security researchers who help us protect our customers and platform. This policy explains how to report a potential vulnerability and the boundaries for good-faith security research.
1. Reporting a Vulnerability
Email reports to security@narrowgatex.com. Please include:
- The affected URL, feature, or service
- Clear reproduction steps and supporting evidence
- The potential impact and any conditions required to reproduce it
- Your preferred name for acknowledgment, if any
Do not include customer data, credentials, or unnecessary sensitive information in the report.
2. Good-Faith Research
Keep testing non-destructive and limited to accounts, systems, and data you own or are explicitly authorized to use. Public-page review, response-header inspection, and limited validation necessary to demonstrate a vulnerability are generally appropriate when they do not affect other users or service availability.
Stop testing and report the issue promptly if you encounter another person’s data, gain unintended elevated access, or could cause disruption.
3. Prohibited Activity
This policy does not authorize:
- Accessing, changing, downloading, retaining, or disclosing another customer’s data
- Phishing, social engineering, credential attacks, or testing against NarrowGateX employees or customers
- Denial of service, excessive automated traffic, destructive testing, malware, or persistence
- Physical attacks, third-party service testing, privacy violations, or disruption of production systems
- Public disclosure before NarrowGateX has had a reasonable opportunity to investigate and remediate the issue
4. Our Response
We will make a reasonable effort to acknowledge credible reports, investigate them, and keep the reporter informed of material remediation. Response and remediation times depend on the issue’s severity, complexity, and affected systems.
We ask that reporters preserve confidentiality while we investigate and coordinate any disclosure with us in advance.
Recognition and Compensation
NarrowGateX does not currently operate a public bug-bounty program. We may acknowledge helpful reports at our discretion, including private thanks or public recognition with the reporter’s permission. Submitting a report does not create an entitlement to payment, compensation, or any other reward.
5. Good-Faith Commitment
When research follows this policy, is intended to improve security, avoids harm, and is reported promptly, NarrowGateX will treat it as good-faith activity. This policy does not provide permission to violate applicable law, access third-party data, or test systems that NarrowGateX does not own.
6. Contact
NarrowGateX Security
Email: security@narrowgatex.com
