Responsible Disclosure

Effective and last updated: July 17, 2026 · Policy version: 0.3

Report a vulnerability

Report security vulnerabilities affecting teraplex.us or a first-party subdomain to security@teraplex.us. Do not send vulnerability details through social media or other public channels.

Include the affected URL or system, reproduction steps, potential impact, and any supporting evidence that does not expose personal information. We aim to acknowledge reports promptly and will prioritize remediation based on severity and risk.

Scope

In scope:

  • teraplex.us and first-party subdomains operated by Teraplex
  • First-party website code, configuration, form handlers, and endpoints operated by Teraplex

Out of scope:

  • Third-party services and systems not operated by Teraplex
  • Social engineering, phishing, physical intrusion, or denial-of-service testing
  • Testing that accesses another person's account or data
  • High-volume automated scanning or activity that degrades service
  • Scanner-only reports or best-practice observations without a reproducible vulnerability

Research guidelines

Teraplex welcomes vulnerability reports, but this policy does not presently authorize active security testing. Do not conduct testing beyond ordinary browser interaction without written authorization from security@teraplex.us.

  • Make a good-faith effort to avoid privacy violations, data loss, and service disruption.
  • Access only the minimum information needed to demonstrate the issue and stop if personal information is encountered.
  • Do not modify, delete, download, or retain data that does not belong to you.
  • Give us reasonable time to investigate and remediate before public disclosure.
  • Comply with applicable law and this policy.

Authorization

Written authorization, if granted, applies only to the systems, time period, methods, and limits stated in that authorization. This policy does not authorize activity against third-party systems, waive the rights of third parties, or protect conduct that violates applicable law.

No bounty commitment

Teraplex does not currently operate a paid bug-bounty program. Submission of a report does not create a right to payment, public recognition, or other compensation.

Contact

security@teraplex.us

Teraplex, LLC

RFC 9116 file: /.well-known/security.txt