Important:
This document is a professional draft, not legal advice. It must be reviewed against elyXion’s final legal entity details, implemented controls, suppliers, customer contracts, and actual operating practices before publication.
1. Purpose
elyXion welcomes good-faith reports of potential vulnerabilities affecting systems and services we operate.
2. Reporting
Send reports to support@elyxion.eu with the affected service, description, reproduction steps, potential impact and non-sensitive evidence.
3. Good-faith Research
Researchers must avoid accessing other parties’ data, disrupting services, destructive testing, social engineering, malware persistence and unnecessary exploitation. Stop testing if sensitive or customer information is encountered.
4. Response
elyXion will seek to acknowledge credible reports, investigate according to risk and coordinate remediation and disclosure where appropriate.
5. Safe-harbour Intent
Where research is conducted in good faith and follows this policy, elyXion intends to treat it as authorised research within the stated scope. Final legal wording requires Dutch legal review.
No bug-bounty payment is promised unless an explicit programme is established.
| Owner: | elyXion |
| Version: | 1.0 |
| Last updated: | 11 Aug 2026 |
| Status: | Draft for legal and operational review |
