Responsible Disclosure
Effective and last updated: July 17, 2026 · Policy version: 0.3
Report a vulnerability
Report security vulnerabilities affecting teraplex.us or a first-party subdomain to security@teraplex.us. Do not send vulnerability details through social media or other public channels.
Include the affected URL or system, reproduction steps, potential impact, and any supporting evidence that does not expose personal information. We aim to acknowledge reports promptly and will prioritize remediation based on severity and risk.
Scope
In scope:
teraplex.usand first-party subdomains operated by Teraplex- First-party website code, configuration, form handlers, and endpoints operated by Teraplex
Out of scope:
- Third-party services and systems not operated by Teraplex
- Social engineering, phishing, physical intrusion, or denial-of-service testing
- Testing that accesses another person's account or data
- High-volume automated scanning or activity that degrades service
- Scanner-only reports or best-practice observations without a reproducible vulnerability
Research guidelines
Teraplex welcomes vulnerability reports, but this policy does not presently authorize active security testing. Do not conduct testing beyond ordinary browser interaction without written authorization from security@teraplex.us.
- Make a good-faith effort to avoid privacy violations, data loss, and service disruption.
- Access only the minimum information needed to demonstrate the issue and stop if personal information is encountered.
- Do not modify, delete, download, or retain data that does not belong to you.
- Give us reasonable time to investigate and remediate before public disclosure.
- Comply with applicable law and this policy.
Authorization
Written authorization, if granted, applies only to the systems, time period, methods, and limits stated in that authorization. This policy does not authorize activity against third-party systems, waive the rights of third parties, or protect conduct that violates applicable law.
No bounty commitment
Teraplex does not currently operate a paid bug-bounty program. Submission of a report does not create a right to payment, public recognition, or other compensation.
Contact
Teraplex, LLC
RFC 9116 file: /.well-known/security.txt