C12 — Vulnerability Disclosure Policy
| Field | Value |
| Document ID | C12 |
| Version | 0.1.0 |
| Status | Draft for UK legal review |
| Classification | Public |
| Document owner | Legal / Compliance / Security |
| Effective date | [Effective Date] |
| Review date | [Effective Date] + 12 months |
| Related documents | B01; C01; C03; C13 |
Xila Ltd — Vulnerability Disclosure Policy
Version 0.1.0 — Draft for UK legal review
Effective date: [Effective Date]
This Policy explains how security researchers and other third parties can responsibly report security vulnerabilities in Xila (the "Platform") operated by Xila Ltd ("Xila", "we", "us", "our"), what scope applies, and how we aim to respond.
We value good-faith security research that helps protect Users. Please read this Policy before testing or reporting issues.
Contact: security@xila.com (may redirect to support@xila.com until a dedicated security inbox is live) · support@xila.com
1. Purpose
Security vulnerabilities can harm Users, partners and the Platform. We want to learn about credible issues quickly so we can investigate, remediate and disclose appropriately.
This Policy describes:
- how to report vulnerabilities;
- what systems are in scope;
- rules for good-faith research;
- our response aims;
- safe harbour intentions for researchers who follow this Policy.
This Policy does not invite uncontrolled testing of third-party systems or social engineering against our staff and Users.
2. How to report a vulnerability
Send reports to security@xila.com with the subject line "Security vulnerability report".
If security@xila.com is not yet operational, use support@xila.com with the same subject line until redirected.
Include, where possible:
1. Description — what the vulnerability is and its potential impact;
2. Location — affected URL, API endpoint, app version or component;
3. Reproduction steps — clear, minimal steps to reproduce;
4. Proof of concept — screenshots, logs or sample requests sufficient to verify the issue, without excessive harm;
5. Your contact details — name or handle, email, optional PGP key;
6. Disclosure preference — whether you prefer coordinated disclosure.
Please encrypt sensitive attachments if you use our published PGP key (when available).
3. Scope
3.1 In scope
Unless otherwise stated, this Policy covers security issues in:
- https://www.xila.com and official Xila web applications;
- official Xila mobile applications distributed by Xila;
- Xila-operated APIs documented for public or authenticated use;
- Xila-owned infrastructure that directly supports the Platform.
Examples of issues we want to hear about:
- authentication or authorisation bypass;
- cross-site scripting (XSS) with demonstrable impact;
- SQL injection or remote code execution;
- insecure direct object references exposing other Users' data;
- significant misconfigurations exposing personal or payment data;
- broken access control in Account, messaging, marketplace or admin functions.
3.2 Out of scope
The following are out of scope unless they produce a clear, novel security impact on Xila systems:
- third-party services, plugins or integrations not operated by Xila (report to the relevant vendor);
- physical security, social engineering, phishing or vishing against staff or Users;
- denial-of-service or load testing without prior written approval;
- spam or volumetric abuse;
- issues requiring unlikely user interaction with no meaningful security consequence;
- clickjacking on pages with no sensitive actions;
- missing security headers or cookie flags without demonstrated exploit;
- automated scanner output without manual validation;
- vulnerabilities in outdated browsers or unsupported client versions;
- brute-forcing credentials except where rate limits are clearly absent and impact is severe;
- issues already known to us or publicly disclosed with patch available.
If unsure, report anyway — we will triage.
4. Rules of engagement
Researchers must:
- make a good-faith effort to avoid privacy violations, service degradation, data destruction or disruption to Users;
- not access, modify or exfiltrate data beyond what is necessary to demonstrate the vulnerability;
- not pivot into other Users' Accounts or internal systems beyond proof of concept;
- not perform social engineering, phishing or physical attacks against Xila personnel, Users or partners;
- not publicly disclose vulnerabilities (no exploit dumping) until we have had reasonable opportunity to investigate and remediate, except where required by law or to prevent imminent harm;
- comply with applicable law.
If you accidentally access another person's data, stop immediately, delete local copies where practicable, and tell us in your report.
5. Safe harbour intention
If you conduct security research in good faith in accordance with this Policy, Xila intends not to pursue legal action against you solely for activities that violate our Terms or Acceptable Use rules to the extent those violations were necessary for your good-faith research.
Safe harbour applies only if you:
- follow the rules in section 4;
- report the issue promptly to security@xila.com;
- do not exploit the vulnerability beyond what is needed for a proof of concept;
- do not publicly disclose before coordinated disclosure (section 7).
Safe harbour does not apply to:
- violations of law unrelated to good-faith research (for example, extortion, data theft for sale, or fraud);
- access to third-party systems outside scope;
- harm caused intentionally or recklessly.
This safe harbour statement is a good-faith commitment, not a contractual waiver of all rights. It may be updated as our programme matures.
6. Our response aims
We aim to:
| Stage | Target |
| Acknowledgement | Within 5 business days of a credible report |
| Initial triage | Within 10 business days — confirm receipt, scope and severity |
| Remediation planning | Prioritise critical issues; timelines depend on complexity |
| Status updates | Periodic updates for serious issues until resolved or declined |
| Resolution notice | Inform reporter when fix is deployed or issue closed |
These are good-faith aims, not guaranteed service levels. Complex, chained or third-party dependency issues may take longer.
We may decline reports that are out of scope, duplicate, or not reproducible.
7. Coordinated disclosure
We prefer coordinated disclosure:
1. You report privately to us;
2. We investigate and develop a fix;
3. We agree a reasonable disclosure timeline with you;
4. We publish security advisories or release notes where appropriate;
5. You may publish research after the agreed date, crediting Xila for collaboration if desired.
Please do not publish exploits, live attack code, or detailed write-ups that could enable mass abuse before remediation without our agreement, except to prevent imminent harm.
We may recognise researchers in release notes or a hall of fame page if they wish and if recognition is appropriate.
8. Bug bounties and rewards
Xila does not currently operate a paid public bug bounty programme. We may introduce rewards or formal programmes in future. This Policy does not create an entitlement to payment for reports.
9. What not to send
Do not send:
- malware;
- bulk personal data exports;
- credentials you obtained unlawfully;
- issues discovered through compromise of real User Accounts without authorisation.
10. Relationship with other policies
Security reports may involve personal data. We process reporter contact details under our [Privacy Policy (C01)](/legal/privacy).
Abuse of security testing to harass Users or attack the Platform violates our [Acceptable Use Policy (C03)](C03-acceptable-use-policy.md) and may result in enforcement.
General complaints about non-security matters are handled under our [Complaints Policy (C13)](C13-complaints-policy.md).
11. Who we are
| Detail | Information |
| Legal name | Xila Ltd |
| Company number | 16799300 |
| Registered office | Suite E, Ground Floor, Profile West, 950 Great West Road, Brentford, United Kingdom TW8 9ES |
| Website | https://www.xila.com |
| Security reports | security@xila.com |
| General support | support@xila.com |
12. Changes
We may update this Policy as our security programme develops. Material changes will be posted on https://www.xila.com.
Change history
| Version | Date | Summary |
| 0.1.0 | 2026-07-15 | Initial Vulnerability Disclosure Policy draft for UK legal review |