Security Disclosure Policy
Effective date: January 1, 2026
We take the security of the Services and our customers' data seriously. If you believe you have found a security vulnerability in bixora.ai, the Bixora portal, our tracking script, or our APIs, we want to hear from you.
1. How to report
Email marketing@bixora.ai with:
- a description of the issue and where it is;
- steps to reproduce, or a proof of concept;
- the potential impact as you understand it;
- your name and contact details (or a handle if you prefer).
We will acknowledge your report within three (3) business days, keep you informed of progress, and tell you when the issue is resolved.
2. What we ask of you
- Make a good-faith effort to avoid privacy violations, data destruction, and interruption of the Services.
- Do not access, modify or download data that is not yours. If you encounter customer data (including call recordings or transcripts), stop, do not keep it, and tell us.
- Do not use social engineering, phishing, physical attacks, or denial-of-service.
- Do not test third-party services we use (advertising platforms, carriers, payment providers) beyond the interface Bixora exposes.
- Give us a reasonable time to fix the issue before disclosing it publicly, and coordinate any disclosure with us.
- Use only accounts you own or are authorized to use. Do not attempt to bypass the invite-only access process.
3. What you can expect from us
- We will not pursue legal action against researchers who follow this Policy in good faith.
- We will work with you to understand and resolve the issue.
- With your permission, we will credit you when the issue is fixed.
- We do not currently run a paid bug-bounty program, but we may offer a token of thanks at our discretion.
4. Out of scope
- Reports from automated scanners without a demonstrated vulnerability.
- Missing best-practice headers or configurations with no demonstrated impact.
- Issues in third-party services outside our control.
- Rate limiting, brute-force, or password-policy findings on public forms that already have bot protection.
- Social engineering of Bixora staff or customers.
Thank you for helping keep Bixora and its customers safe.