Security

Vulnerability disclosure policy

If you find a vulnerability in our services, please let us know. This page explains what the policy covers, how to prepare a report, which tests to avoid and what happens after you report.

Scope

This policy covers the innovix.pl domain and its subdomains - our website, the contact form and the services running under this domain.

Out of scope:

  • our clients' systems - including those we build or test for them; please report the vulnerability to the system owner,
  • third-party services we use (e.g. hosting and email) - please report the vulnerability directly to the provider,
  • Innovix products (NIS2 Shield, LegalAI Analytics, SecureWorkspace) - they are in development and this policy does not cover them yet.

How to report a vulnerability

Email audyty@innovix.pl with the subject line “Vulnerability report”. The same mailbox is listed in our /.well-known/security.txt file (RFC 9116 format). You can write in English or Polish.

We do not publish a PGP key. For that reason, please do not include other people's personal data or full credentials in your report. If your description requires sensitive information, mention this in your first message and we will agree a secure way to share it.

What to include in your report

  • the URL or name of the affected service,
  • the type of vulnerability and its possible impact,
  • steps to reproduce the issue and, where possible, a minimal proof of concept,
  • the date and time of your tests and the IP address you tested from - this helps us tell your tests apart from an attack in our logs,
  • the address we should reply to.

Testing rules

While testing, please:

  • do not run denial-of-service attacks (DoS, DDoS) or load tests,
  • do not access, modify or delete other people's data,
  • do not use social engineering (e.g. phishing or calls to our staff) or physical tests,
  • do not submit the contact form in bulk or run scanners that generate heavy traffic - our server applies rate limits and temporarily blocks IP addresses,
  • test only as far as needed to confirm the vulnerability and do not exploit it further,
  • do not disclose the vulnerability publicly until we have fixed it or agreed a publication date with you.

Good faith

If you act in good faith and in line with this policy, we will not take legal action against you or report you to law enforcement in connection with your report. If you come across other people's data by accident while testing, stop, do not copy it and describe what happened in your report.

This commitment applies to Innovix only - we cannot make it on behalf of our clients or third-party providers.

What happens after you report

  1. Acknowledgement - we will confirm receipt of your report within 5 business days.
  2. Assessment - we will review the report and let you know whether we confirm the vulnerability and how we plan to fix it.
  3. Fix and disclosure - we will tell you once the vulnerability has been fixed; we agree the timing of any publication with you.

We do not run a bug bounty programme and do not pay for reports - but we thank every reporter in our reply.

Research carried out by Innovix

Once a year we run an aggregate study of security headers and TLS configuration on the homepages of companies listed on the Warsaw Stock Exchange - passively, the way a browser does, without scanning or access attempts. Our crawler identifies itself as InnovixHeaderSurvey. The scope, rules and how to opt out are described in the study methodology (in Polish).

How we protect client data

  • EU infrastructure - we keep project systems and data in data centres in the European Union or in the client's own infrastructure.
  • Confidentiality - we sign a non-disclosure agreement (NDA) before discussing system details, and personal data entrusted to us in a project is covered by a data processing agreement under Art. 28 GDPR.
  • Security in the development lifecycle - code review, static analysis and dependency analysis in the CI/CD pipeline, plus a penetration test before release; details on our secure by design page.
  • Encrypted connections - our services run over HTTPS only, with HSTS.

How we process the personal data of people who contact us is explained in our privacy policy. If you are looking for security testing of your own systems, see penetration testing.

Updated

Related