Reporting channel
Email security@relaypbx.com with a subject beginning [SECURITY]. Include product and version, conditions, reproduction, impact, a safe proof of concept and contact details. For encryption, first request the current key or secure channel without sending sensitive material.
Scope
Scope includes public RelayPBX domains, Identity, PBX panel, installer, update agent, official images and applications. Provider systems, customer devices and unofficial deployments are outside scope, but RelayPBX will route a report where possible.
Safe research
- use your own account, tenant and test data;
- stop after first confirmation of access or impact;
- do not download, modify or disclose data belonging to another person;
- no DoS, mass scanning, social engineering, spam, physical attack or live emergency-call testing;
- do not persist access, install a backdoor or bypass payment beyond the minimum vulnerability test;
- do not publish before the coordinated remediation date.
Good-faith research
When you act in good faith, follow this policy and law, and avoid harm, RelayPBX will not initiate claims for the permitted research itself. RelayPBX cannot grant immunity from law or on behalf of third parties. Ask before testing if uncertain.
Our process
RelayPBX targets acknowledgement within 2 business days and initial triage within 5 business days, with updates on material change. Priority follows impact, exploitability and scope. RelayPBX may request detail, coordinate a CVE with an appropriate CNA and agree a publication date.
Credit and rewards
After remediation, RelayPBX may publicly thank the researcher with consent. Version 1.0 has no guaranteed bounty. RelayPBX does not buy vulnerabilities, data or access obtained outside this policy.
Active incident or data
If you encounter an active attack, secret or customer data, stop, do not copy content and mark the email urgent with the minimum identifier and time. Never place evidence in a public issue, repository, ordinary support ticket or social media.