XilaLegal & Policies
Sign In
Trust & SafetyVulnerability Disclosure
Last Updated: Draft — pending solicitor|Version: 0.1.0

Vulnerability Disclosure

Contact Us by Email

Report illegal or harmful content without signing in: Submit a safety report

support@xila.com

Resource Hub

Help & Support
Developer Docs
Legal & Policies
Xila Legal Contact Footer preview

Table of Contents

XilaLegal & Policies
Sign In
Trust & SafetyVulnerability Disclosure
Last Updated: Draft — pending solicitor|Version: 0.1.0

Vulnerability Disclosure

Contact Us by Email

Report illegal or harmful content without signing in: Submit a safety report

support@xila.com

Resource Hub

Help & Support
Developer Docs
Legal & Policies
Xila Legal Contact Footer preview

Table of Contents

XilaLegal & Policies
Sign In
Trust & SafetyVulnerability Disclosure
Last Updated: Draft — pending solicitor|Version: 0.1.0

Vulnerability Disclosure

Contact Us by Email

Report illegal or harmful content without signing in: Submit a safety report

support@xila.com

Resource Hub

Help & Support
Developer Docs
Legal & Policies
Xila Legal Contact Footer preview

Table of Contents

C12 · Effective 16 September 2026

C12 — Vulnerability Disclosure Policy

FieldValue
Document IDC12
Version0.1.0
StatusDraft for UK legal review
ClassificationPublic
Document ownerLegal / Compliance / Security
Effective date[Effective Date]
Review date[Effective Date] + 12 months
Related documentsB01; C01; C03; C13

Xila Ltd — Vulnerability Disclosure Policy

Version 0.1.0 — Draft for UK legal review

Effective date: [Effective Date]

This Policy explains how security researchers and other third parties can responsibly report security vulnerabilities in Xila (the "Platform") operated by Xila Ltd ("Xila", "we", "us", "our"), what scope applies, and how we aim to respond.

We value good-faith security research that helps protect Users. Please read this Policy before testing or reporting issues.

Contact: security@xila.com (may redirect to support@xila.com until a dedicated security inbox is live) · support@xila.com


1. Purpose

Security vulnerabilities can harm Users, partners and the Platform. We want to learn about credible issues quickly so we can investigate, remediate and disclose appropriately.

This Policy describes:

  • how to report vulnerabilities;
  • what systems are in scope;
  • rules for good-faith research;
  • our response aims;
  • safe harbour intentions for researchers who follow this Policy.

This Policy does not invite uncontrolled testing of third-party systems or social engineering against our staff and Users.


2. How to report a vulnerability

Send reports to security@xila.com with the subject line "Security vulnerability report".

If security@xila.com is not yet operational, use support@xila.com with the same subject line until redirected.

Include, where possible:

1. Description — what the vulnerability is and its potential impact;

2. Location — affected URL, API endpoint, app version or component;

3. Reproduction steps — clear, minimal steps to reproduce;

4. Proof of concept — screenshots, logs or sample requests sufficient to verify the issue, without excessive harm;

5. Your contact details — name or handle, email, optional PGP key;

6. Disclosure preference — whether you prefer coordinated disclosure.

Please encrypt sensitive attachments if you use our published PGP key (when available).


3. Scope

3.1 In scope

Unless otherwise stated, this Policy covers security issues in:

  • https://www.xila.com and official Xila web applications;
  • official Xila mobile applications distributed by Xila;
  • Xila-operated APIs documented for public or authenticated use;
  • Xila-owned infrastructure that directly supports the Platform.

Examples of issues we want to hear about:

  • authentication or authorisation bypass;
  • cross-site scripting (XSS) with demonstrable impact;
  • SQL injection or remote code execution;
  • insecure direct object references exposing other Users' data;
  • significant misconfigurations exposing personal or payment data;
  • broken access control in Account, messaging, marketplace or admin functions.

3.2 Out of scope

The following are out of scope unless they produce a clear, novel security impact on Xila systems:

  • third-party services, plugins or integrations not operated by Xila (report to the relevant vendor);
  • physical security, social engineering, phishing or vishing against staff or Users;
  • denial-of-service or load testing without prior written approval;
  • spam or volumetric abuse;
  • issues requiring unlikely user interaction with no meaningful security consequence;
  • clickjacking on pages with no sensitive actions;
  • missing security headers or cookie flags without demonstrated exploit;
  • automated scanner output without manual validation;
  • vulnerabilities in outdated browsers or unsupported client versions;
  • brute-forcing credentials except where rate limits are clearly absent and impact is severe;
  • issues already known to us or publicly disclosed with patch available.

If unsure, report anyway — we will triage.


4. Rules of engagement

Researchers must:

  • make a good-faith effort to avoid privacy violations, service degradation, data destruction or disruption to Users;
  • not access, modify or exfiltrate data beyond what is necessary to demonstrate the vulnerability;
  • not pivot into other Users' Accounts or internal systems beyond proof of concept;
  • not perform social engineering, phishing or physical attacks against Xila personnel, Users or partners;
  • not publicly disclose vulnerabilities (no exploit dumping) until we have had reasonable opportunity to investigate and remediate, except where required by law or to prevent imminent harm;
  • comply with applicable law.

If you accidentally access another person's data, stop immediately, delete local copies where practicable, and tell us in your report.


5. Safe harbour intention

If you conduct security research in good faith in accordance with this Policy, Xila intends not to pursue legal action against you solely for activities that violate our Terms or Acceptable Use rules to the extent those violations were necessary for your good-faith research.

Safe harbour applies only if you:

  • follow the rules in section 4;
  • report the issue promptly to security@xila.com;
  • do not exploit the vulnerability beyond what is needed for a proof of concept;
  • do not publicly disclose before coordinated disclosure (section 7).

Safe harbour does not apply to:

  • violations of law unrelated to good-faith research (for example, extortion, data theft for sale, or fraud);
  • access to third-party systems outside scope;
  • harm caused intentionally or recklessly.

This safe harbour statement is a good-faith commitment, not a contractual waiver of all rights. It may be updated as our programme matures.


6. Our response aims

We aim to:

StageTarget
AcknowledgementWithin 5 business days of a credible report
Initial triageWithin 10 business days — confirm receipt, scope and severity
Remediation planningPrioritise critical issues; timelines depend on complexity
Status updatesPeriodic updates for serious issues until resolved or declined
Resolution noticeInform reporter when fix is deployed or issue closed

These are good-faith aims, not guaranteed service levels. Complex, chained or third-party dependency issues may take longer.

We may decline reports that are out of scope, duplicate, or not reproducible.


7. Coordinated disclosure

We prefer coordinated disclosure:

1. You report privately to us;

2. We investigate and develop a fix;

3. We agree a reasonable disclosure timeline with you;

4. We publish security advisories or release notes where appropriate;

5. You may publish research after the agreed date, crediting Xila for collaboration if desired.

Please do not publish exploits, live attack code, or detailed write-ups that could enable mass abuse before remediation without our agreement, except to prevent imminent harm.

We may recognise researchers in release notes or a hall of fame page if they wish and if recognition is appropriate.


8. Bug bounties and rewards

Xila does not currently operate a paid public bug bounty programme. We may introduce rewards or formal programmes in future. This Policy does not create an entitlement to payment for reports.


9. What not to send

Do not send:

  • malware;
  • bulk personal data exports;
  • credentials you obtained unlawfully;
  • issues discovered through compromise of real User Accounts without authorisation.

10. Relationship with other policies

Security reports may involve personal data. We process reporter contact details under our [Privacy Policy (C01)](/legal/privacy).

Abuse of security testing to harass Users or attack the Platform violates our [Acceptable Use Policy (C03)](C03-acceptable-use-policy.md) and may result in enforcement.

General complaints about non-security matters are handled under our [Complaints Policy (C13)](C13-complaints-policy.md).


11. Who we are

DetailInformation
Legal nameXila Ltd
Company number16799300
Registered officeSuite E, Ground Floor, Profile West, 950 Great West Road, Brentford, United Kingdom TW8 9ES
Websitehttps://www.xila.com
Security reportssecurity@xila.com
General supportsupport@xila.com

12. Changes

We may update this Policy as our security programme develops. Material changes will be posted on https://www.xila.com.


Change history

VersionDateSummary
0.1.02026-07-15Initial Vulnerability Disclosure Policy draft for UK legal review

C12 · Effective 16 September 2026

C12 — Vulnerability Disclosure Policy

FieldValue
Document IDC12
Version0.1.0
StatusDraft for UK legal review
ClassificationPublic
Document ownerLegal / Compliance / Security
Effective date[Effective Date]
Review date[Effective Date] + 12 months
Related documentsB01; C01; C03; C13

Xila Ltd — Vulnerability Disclosure Policy

Version 0.1.0 — Draft for UK legal review

Effective date: [Effective Date]

This Policy explains how security researchers and other third parties can responsibly report security vulnerabilities in Xila (the "Platform") operated by Xila Ltd ("Xila", "we", "us", "our"), what scope applies, and how we aim to respond.

We value good-faith security research that helps protect Users. Please read this Policy before testing or reporting issues.

Contact: security@xila.com (may redirect to support@xila.com until a dedicated security inbox is live) · support@xila.com


1. Purpose

Security vulnerabilities can harm Users, partners and the Platform. We want to learn about credible issues quickly so we can investigate, remediate and disclose appropriately.

This Policy describes:

  • how to report vulnerabilities;
  • what systems are in scope;
  • rules for good-faith research;
  • our response aims;
  • safe harbour intentions for researchers who follow this Policy.

This Policy does not invite uncontrolled testing of third-party systems or social engineering against our staff and Users.


2. How to report a vulnerability

Send reports to security@xila.com with the subject line "Security vulnerability report".

If security@xila.com is not yet operational, use support@xila.com with the same subject line until redirected.

Include, where possible:

1. Description — what the vulnerability is and its potential impact;

2. Location — affected URL, API endpoint, app version or component;

3. Reproduction steps — clear, minimal steps to reproduce;

4. Proof of concept — screenshots, logs or sample requests sufficient to verify the issue, without excessive harm;

5. Your contact details — name or handle, email, optional PGP key;

6. Disclosure preference — whether you prefer coordinated disclosure.

Please encrypt sensitive attachments if you use our published PGP key (when available).


3. Scope

3.1 In scope

Unless otherwise stated, this Policy covers security issues in:

  • https://www.xila.com and official Xila web applications;
  • official Xila mobile applications distributed by Xila;
  • Xila-operated APIs documented for public or authenticated use;
  • Xila-owned infrastructure that directly supports the Platform.

Examples of issues we want to hear about:

  • authentication or authorisation bypass;
  • cross-site scripting (XSS) with demonstrable impact;
  • SQL injection or remote code execution;
  • insecure direct object references exposing other Users' data;
  • significant misconfigurations exposing personal or payment data;
  • broken access control in Account, messaging, marketplace or admin functions.

3.2 Out of scope

The following are out of scope unless they produce a clear, novel security impact on Xila systems:

  • third-party services, plugins or integrations not operated by Xila (report to the relevant vendor);
  • physical security, social engineering, phishing or vishing against staff or Users;
  • denial-of-service or load testing without prior written approval;
  • spam or volumetric abuse;
  • issues requiring unlikely user interaction with no meaningful security consequence;
  • clickjacking on pages with no sensitive actions;
  • missing security headers or cookie flags without demonstrated exploit;
  • automated scanner output without manual validation;
  • vulnerabilities in outdated browsers or unsupported client versions;
  • brute-forcing credentials except where rate limits are clearly absent and impact is severe;
  • issues already known to us or publicly disclosed with patch available.

If unsure, report anyway — we will triage.


4. Rules of engagement

Researchers must:

  • make a good-faith effort to avoid privacy violations, service degradation, data destruction or disruption to Users;
  • not access, modify or exfiltrate data beyond what is necessary to demonstrate the vulnerability;
  • not pivot into other Users' Accounts or internal systems beyond proof of concept;
  • not perform social engineering, phishing or physical attacks against Xila personnel, Users or partners;
  • not publicly disclose vulnerabilities (no exploit dumping) until we have had reasonable opportunity to investigate and remediate, except where required by law or to prevent imminent harm;
  • comply with applicable law.

If you accidentally access another person's data, stop immediately, delete local copies where practicable, and tell us in your report.


5. Safe harbour intention

If you conduct security research in good faith in accordance with this Policy, Xila intends not to pursue legal action against you solely for activities that violate our Terms or Acceptable Use rules to the extent those violations were necessary for your good-faith research.

Safe harbour applies only if you:

  • follow the rules in section 4;
  • report the issue promptly to security@xila.com;
  • do not exploit the vulnerability beyond what is needed for a proof of concept;
  • do not publicly disclose before coordinated disclosure (section 7).

Safe harbour does not apply to:

  • violations of law unrelated to good-faith research (for example, extortion, data theft for sale, or fraud);
  • access to third-party systems outside scope;
  • harm caused intentionally or recklessly.

This safe harbour statement is a good-faith commitment, not a contractual waiver of all rights. It may be updated as our programme matures.


6. Our response aims

We aim to:

StageTarget
AcknowledgementWithin 5 business days of a credible report
Initial triageWithin 10 business days — confirm receipt, scope and severity
Remediation planningPrioritise critical issues; timelines depend on complexity
Status updatesPeriodic updates for serious issues until resolved or declined
Resolution noticeInform reporter when fix is deployed or issue closed

These are good-faith aims, not guaranteed service levels. Complex, chained or third-party dependency issues may take longer.

We may decline reports that are out of scope, duplicate, or not reproducible.


7. Coordinated disclosure

We prefer coordinated disclosure:

1. You report privately to us;

2. We investigate and develop a fix;

3. We agree a reasonable disclosure timeline with you;

4. We publish security advisories or release notes where appropriate;

5. You may publish research after the agreed date, crediting Xila for collaboration if desired.

Please do not publish exploits, live attack code, or detailed write-ups that could enable mass abuse before remediation without our agreement, except to prevent imminent harm.

We may recognise researchers in release notes or a hall of fame page if they wish and if recognition is appropriate.


8. Bug bounties and rewards

Xila does not currently operate a paid public bug bounty programme. We may introduce rewards or formal programmes in future. This Policy does not create an entitlement to payment for reports.


9. What not to send

Do not send:

  • malware;
  • bulk personal data exports;
  • credentials you obtained unlawfully;
  • issues discovered through compromise of real User Accounts without authorisation.

10. Relationship with other policies

Security reports may involve personal data. We process reporter contact details under our [Privacy Policy (C01)](/legal/privacy).

Abuse of security testing to harass Users or attack the Platform violates our [Acceptable Use Policy (C03)](C03-acceptable-use-policy.md) and may result in enforcement.

General complaints about non-security matters are handled under our [Complaints Policy (C13)](C13-complaints-policy.md).


11. Who we are

DetailInformation
Legal nameXila Ltd
Company number16799300
Registered officeSuite E, Ground Floor, Profile West, 950 Great West Road, Brentford, United Kingdom TW8 9ES
Websitehttps://www.xila.com
Security reportssecurity@xila.com
General supportsupport@xila.com

12. Changes

We may update this Policy as our security programme develops. Material changes will be posted on https://www.xila.com.


Change history

VersionDateSummary
0.1.02026-07-15Initial Vulnerability Disclosure Policy draft for UK legal review

C12 · Effective 16 September 2026

C12 — Vulnerability Disclosure Policy

FieldValue
Document IDC12
Version0.1.0
StatusDraft for UK legal review
ClassificationPublic
Document ownerLegal / Compliance / Security
Effective date[Effective Date]
Review date[Effective Date] + 12 months
Related documentsB01; C01; C03; C13

Xila Ltd — Vulnerability Disclosure Policy

Version 0.1.0 — Draft for UK legal review

Effective date: [Effective Date]

This Policy explains how security researchers and other third parties can responsibly report security vulnerabilities in Xila (the "Platform") operated by Xila Ltd ("Xila", "we", "us", "our"), what scope applies, and how we aim to respond.

We value good-faith security research that helps protect Users. Please read this Policy before testing or reporting issues.

Contact: security@xila.com (may redirect to support@xila.com until a dedicated security inbox is live) · support@xila.com


1. Purpose

Security vulnerabilities can harm Users, partners and the Platform. We want to learn about credible issues quickly so we can investigate, remediate and disclose appropriately.

This Policy describes:

  • how to report vulnerabilities;
  • what systems are in scope;
  • rules for good-faith research;
  • our response aims;
  • safe harbour intentions for researchers who follow this Policy.

This Policy does not invite uncontrolled testing of third-party systems or social engineering against our staff and Users.


2. How to report a vulnerability

Send reports to security@xila.com with the subject line "Security vulnerability report".

If security@xila.com is not yet operational, use support@xila.com with the same subject line until redirected.

Include, where possible:

1. Description — what the vulnerability is and its potential impact;

2. Location — affected URL, API endpoint, app version or component;

3. Reproduction steps — clear, minimal steps to reproduce;

4. Proof of concept — screenshots, logs or sample requests sufficient to verify the issue, without excessive harm;

5. Your contact details — name or handle, email, optional PGP key;

6. Disclosure preference — whether you prefer coordinated disclosure.

Please encrypt sensitive attachments if you use our published PGP key (when available).


3. Scope

3.1 In scope

Unless otherwise stated, this Policy covers security issues in:

  • https://www.xila.com and official Xila web applications;
  • official Xila mobile applications distributed by Xila;
  • Xila-operated APIs documented for public or authenticated use;
  • Xila-owned infrastructure that directly supports the Platform.

Examples of issues we want to hear about:

  • authentication or authorisation bypass;
  • cross-site scripting (XSS) with demonstrable impact;
  • SQL injection or remote code execution;
  • insecure direct object references exposing other Users' data;
  • significant misconfigurations exposing personal or payment data;
  • broken access control in Account, messaging, marketplace or admin functions.

3.2 Out of scope

The following are out of scope unless they produce a clear, novel security impact on Xila systems:

  • third-party services, plugins or integrations not operated by Xila (report to the relevant vendor);
  • physical security, social engineering, phishing or vishing against staff or Users;
  • denial-of-service or load testing without prior written approval;
  • spam or volumetric abuse;
  • issues requiring unlikely user interaction with no meaningful security consequence;
  • clickjacking on pages with no sensitive actions;
  • missing security headers or cookie flags without demonstrated exploit;
  • automated scanner output without manual validation;
  • vulnerabilities in outdated browsers or unsupported client versions;
  • brute-forcing credentials except where rate limits are clearly absent and impact is severe;
  • issues already known to us or publicly disclosed with patch available.

If unsure, report anyway — we will triage.


4. Rules of engagement

Researchers must:

  • make a good-faith effort to avoid privacy violations, service degradation, data destruction or disruption to Users;
  • not access, modify or exfiltrate data beyond what is necessary to demonstrate the vulnerability;
  • not pivot into other Users' Accounts or internal systems beyond proof of concept;
  • not perform social engineering, phishing or physical attacks against Xila personnel, Users or partners;
  • not publicly disclose vulnerabilities (no exploit dumping) until we have had reasonable opportunity to investigate and remediate, except where required by law or to prevent imminent harm;
  • comply with applicable law.

If you accidentally access another person's data, stop immediately, delete local copies where practicable, and tell us in your report.


5. Safe harbour intention

If you conduct security research in good faith in accordance with this Policy, Xila intends not to pursue legal action against you solely for activities that violate our Terms or Acceptable Use rules to the extent those violations were necessary for your good-faith research.

Safe harbour applies only if you:

  • follow the rules in section 4;
  • report the issue promptly to security@xila.com;
  • do not exploit the vulnerability beyond what is needed for a proof of concept;
  • do not publicly disclose before coordinated disclosure (section 7).

Safe harbour does not apply to:

  • violations of law unrelated to good-faith research (for example, extortion, data theft for sale, or fraud);
  • access to third-party systems outside scope;
  • harm caused intentionally or recklessly.

This safe harbour statement is a good-faith commitment, not a contractual waiver of all rights. It may be updated as our programme matures.


6. Our response aims

We aim to:

StageTarget
AcknowledgementWithin 5 business days of a credible report
Initial triageWithin 10 business days — confirm receipt, scope and severity
Remediation planningPrioritise critical issues; timelines depend on complexity
Status updatesPeriodic updates for serious issues until resolved or declined
Resolution noticeInform reporter when fix is deployed or issue closed

These are good-faith aims, not guaranteed service levels. Complex, chained or third-party dependency issues may take longer.

We may decline reports that are out of scope, duplicate, or not reproducible.


7. Coordinated disclosure

We prefer coordinated disclosure:

1. You report privately to us;

2. We investigate and develop a fix;

3. We agree a reasonable disclosure timeline with you;

4. We publish security advisories or release notes where appropriate;

5. You may publish research after the agreed date, crediting Xila for collaboration if desired.

Please do not publish exploits, live attack code, or detailed write-ups that could enable mass abuse before remediation without our agreement, except to prevent imminent harm.

We may recognise researchers in release notes or a hall of fame page if they wish and if recognition is appropriate.


8. Bug bounties and rewards

Xila does not currently operate a paid public bug bounty programme. We may introduce rewards or formal programmes in future. This Policy does not create an entitlement to payment for reports.


9. What not to send

Do not send:

  • malware;
  • bulk personal data exports;
  • credentials you obtained unlawfully;
  • issues discovered through compromise of real User Accounts without authorisation.

10. Relationship with other policies

Security reports may involve personal data. We process reporter contact details under our [Privacy Policy (C01)](/legal/privacy).

Abuse of security testing to harass Users or attack the Platform violates our [Acceptable Use Policy (C03)](C03-acceptable-use-policy.md) and may result in enforcement.

General complaints about non-security matters are handled under our [Complaints Policy (C13)](C13-complaints-policy.md).


11. Who we are

DetailInformation
Legal nameXila Ltd
Company number16799300
Registered officeSuite E, Ground Floor, Profile West, 950 Great West Road, Brentford, United Kingdom TW8 9ES
Websitehttps://www.xila.com
Security reportssecurity@xila.com
General supportsupport@xila.com

12. Changes

We may update this Policy as our security programme develops. Material changes will be posted on https://www.xila.com.


Change history

VersionDateSummary
0.1.02026-07-15Initial Vulnerability Disclosure Policy draft for UK legal review