Policies & legal.
The operating basis for every engagement. Read what you need, ignore what you do not.
Responsible Disclosure Policy
We coordinate with affected organizations privately. No public disclosure until remediation is validated and, where relevant, the organization has communicated with its users. We do not access, modify, or retain data beyond what is necessary to demonstrate the issue.
Privacy Policy
We collect only the information necessary to communicate with you and deliver engagements. We do not sell or share personal data. Engagement artifacts are retained under the terms of the executed NDA.
Terms of Engagement
All engagements are governed by a written scope-of-work signed by both parties. Deliverables, testing windows, and access constraints are agreed prior to any active testing.
Legal
Xyrix Security operates under a formal legal entity. Testing is only performed under explicit written authorization from the asset owner.
Security.txt
Our security.txt is published at /.well-known/security.txt and lists our current contact channels.
Open security.txt →NDA
A mutual NDA is executed before scoping details are exchanged. We can work under your NDA or provide ours.
Responsible AI Usage
AI is used internally as tooling, never as a substitute for validation. Every finding is reproduced and confirmed manually before disclosure or reporting.
Acceptable Use
This website is provided for informational purposes. Testing activity against Xyrix infrastructure is not authorized outside of an executed engagement.
Accessibility
We aim for WCAG 2.1 AA compliance across informational pages. Report barriers to nolan@xyrix.io and we will address them promptly.