Skip to main content

Responsible disclosure

Responsible Disclosure

Report security concerns through a structured disclosure process so issues can be reviewed responsibly.

Secure account verification Reviewed opportunities Support when you need it

Report a suspected security issue

Use the Contact form and begin your message with “Security concern”. Include the affected page, safe steps to reproduce the issue, the possible impact and a reliable reply address. Please keep the report factual and avoid unnecessary personal information.

Open Security Contact Form

What to report

  • A suspected vulnerability affecting an IXF website or account experience.
  • A security control that appears not to work as intended.
  • A credible risk to customer information, authentication or important actions.

Testing that is not permitted

  • Do not access, copy, change or delete another person’s information.
  • Do not disrupt IXF services, overwhelm systems or use destructive techniques.
  • Do not use social engineering, phishing, credential attacks or physical intrusion.
  • Do not upload malware or expose a suspected issue publicly before IXF can assess it.

What happens after you report

  1. Step 1

    Receive

    IXF receives the report through the security contact route.

  2. Step 2

    Assess

    The team reviews scope, impact and safe reproduction information.

  3. Step 3

    Respond

    IXF coordinates next steps and may contact you for clarification.

Good-faith expectations: act carefully, minimise data access, stop if customer information is exposed and keep the matter confidential while it is assessed. Response timing depends on severity and investigation needs.