Vulnerability Disclosure Policy
heimdallX is a security product. If you find a vulnerability in our service, we want to hear about it — and we will not take legal action against anyone who researches and reports in good faith. This is the policy the `Policy:` field of /.well-known/security.txt points to.
1. How to report
- Email: [email protected] — include reproduction steps and the impact if you can. This is the same address as the Contact field of /.well-known/security.txt
- Acknowledgement: within 3 business days
- First assessment (valid / not valid, severity): within 10 business days
- We will tell you when a fix ships
We do not run a paid bounty programme yet. We are glad to credit you publicly if you would like that.
2. Scope
- heimdallx.ai and its subdomains
- 021flow.com and its subdomains
- The public API (key-authenticated endpoints)
Third-party services we do not operate — payment processing, cloud providers — are out of scope; please follow their own policies.
3. Please do not
- Access, modify or delete another customer's data. If you can demonstrate that you could, stop there and tell us.
- Run denial-of-service, load tests, or high-volume automated scanning
- Social-engineer or phish our staff or customers
- Attempt physical intrusion
- Exfiltrate more data than is needed to demonstrate the issue
4. Safe harbour
If you research and report in line with this policy, we consider your activity authorised, we will not pursue legal action, and we will not report you to law enforcement. If a third party raises a claim, we will make it known that you followed this policy.
If you access customer data by accident, stop, tell us, and delete it. That is still within good faith.
5. Disclosure
We welcome coordinated publication once a fix has shipped. Our default is 90 days from your report, after which you are free to publish whether or not we have finished. If you believe an earlier disclosure is warranted, tell us and we will discuss it.
Effective Date: Not yet confirmed, 2026