Security / Coordinated Disclosure
Report a vulnerability
We welcome good-faith security research. If you believe you have found a security vulnerability in AxisSynapse, please report it to us so we can fix it and protect our customers.
How to report
Email security@axissynapse.com with a description, reproduction steps, and impact. Our machine-readable manifest lives at /.well-known/security.txt (RFC 9116).
What to expect
- Acknowledgement within 2 business days.
- A triage decision and, where accepted, a remediation timeline by severity.
| Severity | Target remediation |
|---|---|
| Critical | ≤ 7 days |
| High | ≤ 30 days |
| Medium | ≤ 90 days |
| Low | ≤ 180 days |
Scope & safe harbor
We will not pursue legal action against researchers who act in good faith and comply with this policy. In scope: the AxisSynapse production application and API. Please:
- Test only against your own account/workspace or with explicit permission.
- Do not access, modify, or destroy data belonging to others.
- Do not degrade the service (no DoS, no spam, no social engineering of staff).
- Give us a reasonable time to remediate before any public disclosure.
This page is the human-readable companion to our Trust Center. Program details are governed by our internal Vulnerability Disclosure & Management policy.