Responsible Disclosure Policy
Sentrix protects institutions under supervision, so we take the security of our platform seriously and welcome the work of security researchers. This policy explains how to report a vulnerability to us safely and what you can expect in return.
Last updated: 22 July 2026 · Governing law: United Arab Emirates
1. Our commitment
If you discover a security vulnerability in a Sentrix service, we want to hear about it. We will investigate every good-faith report, keep you informed of our progress, and will not pursue or support legal action against researchers who follow this policy. We treat the security of our customers' data as a first-order priority.
2. Scope
This policy covers the Sentrix marketing site and application at sentrix.world and its documented API. Third-party services we rely on (for example our hosting and database providers) are governed by their own disclosure programmes; please report issues in those platforms to the relevant vendor, and let us know if a Sentrix configuration is implicated.
3. How to report
Email security@sentrix.world with:
- A clear description of the issue and the affected endpoint, page or component.
- Step-by-step instructions to reproduce, including any proof-of-concept.
- The potential impact as you see it, and any suggested remediation.
- Your contact details, so we can follow up and credit you if you wish.
Please do not disclose the issue publicly until we have had a reasonable opportunity to remediate it and have agreed a coordinated disclosure timeline with you.
4. Rules of engagement
When testing, please:
- Do act in good faith, stay within scope, and stop as soon as you have demonstrated a vulnerability.
- Do not access, modify, exfiltrate or destroy data that is not your own; use only test accounts you control.
- Do not run denial-of-service, spam, social-engineering, physical or automated high-volume attacks that degrade the service for others.
- Do not violate the privacy of our customers or their end users; if you encounter personal data, stop and report it.
5. What to expect from us
- Acknowledgement — we aim to confirm receipt within 3 business days.
- Assessment — we triage, validate and prioritise the report and keep you updated.
- Remediation — we work to fix confirmed issues on a timeline proportionate to severity, and we will let you know when a fix has shipped.
- Recognition — with your permission, we are happy to credit your contribution. We do not currently operate a paid bug-bounty programme.
6. Safe harbour
We consider security research and vulnerability disclosure conducted in accordance with this policy to be authorised, and we will not treat it as a breach of our Acceptable Use Policy or Terms of Service. If a third party brings action against you for activity conducted in good faith under this policy, we will make our authorisation known. This policy does not authorise action inconsistent with applicable law.
7. Contact
Security reports: security@sentrix.world. For a broader view of our controls, see our Information Security overview.