Security / Responsible reporting

Protect the system.
Protect the client.

CRILOX separates public portfolio evidence from private operational data and uses explicit approval boundaries for sensitive client and payment workflows.

01

Report a security concern.

If you believe a CRILOX-managed public system exposes data, authentication, payment or infrastructure risk, send a concise report with the affected URL, observed behaviour and safe reproduction details. Do not include secrets or unrelated personal data.

Email a report

02

Please avoid destructive testing.

Do not disrupt availability, access accounts or data you do not own, attempt social engineering, perform denial-of-service activity, or continue testing after you have enough evidence to explain the issue. A report is not authorization to test a third-party or client-owned system.

03

Public disclosure stays bounded.

Portfolio case studies intentionally exclude credentials, private client records, payment data and internal security topology. Where a client engagement has stricter confidentiality requirements, those requirements take priority over portfolio detail.

04

Operational controls are layered.

The CRILOX manager is not part of the indexable public site, sensitive manager responses are marked private/no-store, client records use database access policies, and important commercial transitions such as delivery authorization are also protected at the data boundary rather than only in the interface.