Cybersecurity · Penetration testing
Penetration testing
Penetration testing services for web and mobile apps, APIs, infrastructure, cloud and source code. OWASP and PTES, evidence-based reports and retests.
Security
If you find a vulnerability in our services, please let us know. This page explains what the policy covers, how to prepare a report, which tests to avoid and what happens after you report.
This policy covers the innovix.pl domain and its subdomains - our website, the contact form and the services running under this domain.
Out of scope:
Email audyty@innovix.pl with the subject line “Vulnerability report”. The same mailbox is listed in our /.well-known/security.txt file (RFC 9116 format). You can write in English or Polish.
We do not publish a PGP key. For that reason, please do not include other people's personal data or full credentials in your report. If your description requires sensitive information, mention this in your first message and we will agree a secure way to share it.
While testing, please:
If you act in good faith and in line with this policy, we will not take legal action against you or report you to law enforcement in connection with your report. If you come across other people's data by accident while testing, stop, do not copy it and describe what happened in your report.
This commitment applies to Innovix only - we cannot make it on behalf of our clients or third-party providers.
We do not run a bug bounty programme and do not pay for reports - but we thank every reporter in our reply.
Once a year we run an aggregate study of security headers and TLS configuration on the homepages of companies listed on the Warsaw Stock Exchange - passively, the way a browser does, without scanning or access attempts. Our crawler identifies itself as InnovixHeaderSurvey. The scope, rules and how to opt out are described in the study methodology (in Polish).
How we process the personal data of people who contact us is explained in our privacy policy. If you are looking for security testing of your own systems, see penetration testing.
Updated
Cybersecurity · Penetration testing
Penetration testing services for web and mobile apps, APIs, infrastructure, cloud and source code. OWASP and PTES, evidence-based reports and retests.
Contact
Contact Innovix in Wrocław, Poland, about custom software, penetration testing or NIS2/KSC audits. We reply within 24 hours on business days.
Legal document
Innovix sp. z o.o. privacy policy: what personal data we process and why, how long we keep it, cookie-free statistics and your rights under the GDPR.