Responsible disclosure
Responsible Disclosure
Report security concerns through a structured disclosure process so issues can be reviewed responsibly.
Report a suspected security issue
Use the Contact form and begin your message with “Security concern”. Include the affected page, safe steps to reproduce the issue, the possible impact and a reliable reply address. Please keep the report factual and avoid unnecessary personal information.
Open Security Contact FormWhat to report
- A suspected vulnerability affecting an IXF website or account experience.
- A security control that appears not to work as intended.
- A credible risk to customer information, authentication or important actions.
Testing that is not permitted
- Do not access, copy, change or delete another person’s information.
- Do not disrupt IXF services, overwhelm systems or use destructive techniques.
- Do not use social engineering, phishing, credential attacks or physical intrusion.
- Do not upload malware or expose a suspected issue publicly before IXF can assess it.
What happens after you report
- Step 1
Receive
IXF receives the report through the security contact route.
- Step 2
Assess
The team reviews scope, impact and safe reproduction information.
- Step 3
Respond
IXF coordinates next steps and may contact you for clarification.
Good-faith expectations: act carefully, minimise data access, stop if customer information is exposed and keep the matter confidential while it is assessed. Response timing depends on severity and investigation needs.