Responsible disclosure.
Magdox treats security as core to how we operate. Independent researchers often find things our own team misses, and we want to make it easy and safe for you to tell us about them.
Report it
Email [email protected] with a clear description, steps to reproduce, proof of concept, and the impact you believe it has. Include your name or handle and whether you'd like public credit.
We acknowledge
We acknowledge every report within 3 business days and triage within 5 business days. We keep you informed as we investigate.
We fix and credit
Once a valid report is resolved, we add your name to our Hall of Fame (with your permission) as thanks for the responsible disclosure.
No monetary rewards
Magdox does not currently run a paid bug bounty program. We are not able to offer cash rewards for vulnerability reports at this time. What we do offer is public recognition. Every researcher who submits a valid, previously unreported vulnerability is credited on our Hall of Fame page, unless they prefer to stay anonymous. We may introduce paid rewards in the future.
In scope
- magdox.io and its public marketing pages
- app.magdox.io and its authenticated application surface
- Publicly documented API endpoints under the magdox.io domain
Out of scope
- mail.magdox.io: this subdomain is operated by our email hosting provider, not by us. Vulnerabilities there belong to their security team.
- Social engineering, phishing, or physical attacks against Magdox staff or offices
- Denial-of-service or load-testing traffic of any kind
- Automated scanning that generates high-volume traffic without prior coordination with [email protected]
- Third-party services we integrate with but do not operate (e.g. Dodo Payments, HubSpot, Cal.com, your own AI provider). Report issues with those services directly to the company that runs them.
Severity classification & resolution SLAs
We triage every report by real-world impact. The table below shows how we categorize severity and our target resolution timeframes. These are best-effort targets, not guarantees.
| Severity | CVSS | Target Fix | Example Vulnerabilities |
|---|---|---|---|
| Critical | 9.0–10.0 | 14 business days | Remote code execution; SQL injection exposing PII or customer data; authentication bypass allowing cross-tenant access; bulk data exfiltration |
| High | 7.0–8.9 | 30 business days | Authentication or authorization bypass (single tenant); account takeover without user interaction; IDOR exposing sensitive data; privilege escalation; stored XSS; SSRF reaching internal infrastructure; API key or session token exposure |
| Medium | 4.0–6.9 | 60 business days | Account takeover requiring user interaction; IDOR exposing non-sensitive data; reflected or DOM XSS capable of stealing session cookies; subdomain takeover on active domains; formula or host-header injection |
| Low | 0.1–3.9 | 90 business days | Path traversal to non-sensitive files; IDOR on non-sensitive references; subdomain takeover on inactive domains; captcha bypass |
What we generally do not need reports about
- Rate limiting, unless you can demonstrate it leads to real data loss or measurable business impact
- Open redirects on their own
- Clickjacking or issues that only work through clickjacking
- Missing SPF, DKIM, or DMARC hardening beyond what we already publish
- Username or email enumeration on public forms
- Self-XSS that requires the victim to paste something into their own browser console
- Descriptive error messages or stack traces that do not expose secrets or user data
- Best-practice suggestions that do not themselves put data or accounts at risk, such as a missing HSTS preload flag
- Anything found using an out-of-date patch, reported within 30 days of the patch becoming available
If you are not sure whether something counts, send it anyway. We would rather see a report that turns out to be low impact than miss a real one.
Ground rules
We ask that you:
- Only test against accounts and data you own, or that you have explicit permission to test against
- Make a good-faith effort to avoid privacy violations, data destruction, and any interruption or degradation of our service
- Avoid social engineering of any kind, including phishing our staff or customers
- Give us a reasonable amount of time to fix an issue before discussing it publicly
- Send one report per vulnerability, unless several smaller issues need to be reported together to show their combined impact
- Avoid running aggressive, high-volume automated scanners against our production systems. Manual testing or a scanner configured to respect rate limits is fine.
Safe harbor
If you follow the ground rules above in good faith, we will not pursue legal action against you for your research, and we will not suspend your account because of it. If a third party takes legal action against you for activity that was consistent with this policy, we will do what we can to make clear to them that your work was authorized.
Confidentiality
If you report a vulnerability to us, you may come across information that is not public. This could include details about how our systems are built, our product roadmap, or other non-public technical or business information.
Please keep anything you learn through this process confidential. Do not publish it, share it, or use it for anything other than helping us fix the issue you found, for five years from when you learned it. Any technical materials or write-ups you prepare as part of a report, along with any copies you make of information we share with you, remain our property, and we may ask you to delete or return them once the issue is resolved.
If you are found to have broken this confidentiality obligation, or misused a vulnerability you found instead of reporting it responsibly, we reserve the right to take legal action, including seeking an injunction or other court order, since a breach here can cause harm that is difficult to fix with money alone.
Governing law
This policy is governed by the laws of India, including the Information Technology Act, 2000. Any dispute arising from it will be handled in the competent courts of West Bengal, India.
Ready to report something? [email protected]
Thank you for taking the time to help keep Magdox and our customers safe.