If you believe you have found a vulnerability in our public-facing systems, we want to hear from you, and we will treat you like a professional. Report it privately to security@objexis.ai. Include a description of the issue, steps to reproduce it, your assessment of the impact, and the name or handle you want credited if you would like public acknowledgement.
In scope: objexis.ai, its subdomains, and the public web infrastructure we operate. If it is reachable from the open internet and belongs to us, it is fair game for good-faith research.
Out of scope: Deployed defence systems and fielded hardware. Attempting to access, acquire, track, or probe operational systems is not research, and it is not authorized. Also out of scope: denial of service, social engineering of our people or partners, physical intrusion, and third-party services we do not control.
Our commitment: Acknowledgement within 3 business days. A triage assessment within 10 business days. Straight answers about what we found and when it will be fixed. You will not be met with silence or a legal letter for doing the right thing.
Coordinated timeline: We ask for a standard 90-day window before public disclosure, and we will work with you on timing if a fix needs longer or lands sooner. Credit is yours if you want it, anonymity is yours if you prefer it.
Safe harbour: Research conducted in good faith under this policy is authorized. We will not pursue legal action against researchers who respect scope, access only the minimum data needed to demonstrate an issue, do not degrade service, and report promptly and privately.
No bounty, no pretence: We do not currently run a paid bounty program, and we will not pretend otherwise. What we offer is direct engagement with the engineers who built the thing, a fast fix, and public credit. When that changes, this page will say so.