Trust & responsibility

Responsible Disclosure Policy

Report a suspected vulnerability privately. Reporting an issue is not permission to investigate, exploit or test our systems.

Ordinexis Sdn Bhd

Last updated

At a glance

Report privately
Email hey@ordinexis.com with a concise, redacted description.
Stop at discovery
Do not investigate further or access additional information.
No testing permission
This is a reporting channel, not a security research programme.

A reporting channel, not an invitation to test

Ordinexis Sdn Bhd accepts reports of suspected security vulnerabilities encountered during ordinary, permitted use of our websites or services, or otherwise brought to your attention without further probing. You may report what you have already observed; you do not need to prove exploitation or collect additional evidence.

This policy does not authorise security research, vulnerability scanning, penetration testing, audits or exploitation. No system is placed in scope for public security testing by this policy. Our Security Audit Policy explains the restrictions. A reporting email address, a public demo or a reply from our team is not permission to test.

If you encounter a possible vulnerability

  • Stop the activity that revealed the issue. Do not repeat it, change identifiers or inputs, or try it against another account to confirm its impact.
  • Do not view, copy, download, change or delete information that you are not entitled to access.
  • Do not attempt privilege escalation, persistence, lateral movement, bypasses, service disruption or access to other systems.
  • Do not share exposed information or invite others to reproduce the issue.

If sensitive information has already appeared unexpectedly, do not obtain more. Tell us what category of information was exposed without including the information itself. Protect any material already received from further access, and contact us about appropriate handling, subject to applicable legal obligations.

How to send a report

Email hey@ordinexis.com with the subject "Responsible disclosure". Include only information you already have:

  • The affected product, page or endpoint, with credentials and sensitive query parameters removed.
  • The approximate date, time and time zone of the observation.
  • What you expected and what happened during your normal use.
  • The potential impact, clearly separated from anything you have not verified.
  • A redacted screenshot or short description, if it can be shared without exposing personal or confidential information.
  • A reply address if you would like us to contact you.

Do not send passwords, access tokens, private keys, customer records, full database extracts or malicious attachments. Email is not a place to upload sensitive evidence. Contact us first if a safer transfer method is needed; do not obtain extra material for the report.

What happens after a report

We assess reports using the information available, the affected service and the potential impact. We may request clarification or coordinate with relevant service providers. A request for an explanation is not a request to repeat an action or perform more testing.

Submitting a report does not guarantee a particular response time, remediation date, outcome or access to investigation details. We may be unable to share information about other customers, security controls or an active investigation. Ordinary support questions and incorrect AI answers can also be sent to our team; they do not necessarily indicate a security vulnerability.

Private coordination and protecting others

Please give our team the opportunity to assess the report and coordinate any remediation before publishing technical details that could enable misuse. Do not publish personal information, credentials, confidential records or instructions that expose people to an active risk.

Do not threaten exploitation, disruption or release of data to obtain payment or another benefit. This policy does not restrict disclosures required by law, lawful reports to regulators or law enforcement, or other legally protected reporting.

No bounty, safe harbour or third-party authority

This policy does not create a bug bounty programme or promise payment, a reward, public credit, legal immunity or a safe harbour for testing. Reporting an issue does not retrospectively authorise the activity that discovered it. Acknowledgement, silence or ongoing correspondence is not approval for further activity.

We cannot authorise access to customer systems, hosting providers, model providers or other third-party services. A connection to an Ordinexis product, a shared brand reference or a link from our website does not grant rights over those systems.

Contact, privacy and related policies

Reports are handled by Ordinexis Sdn Bhd through hey@ordinexis.com. Information in a report may be used to investigate the concern, protect services and communicate with relevant parties as described in our Privacy Policy. Share the minimum personal information needed.

Read this policy alongside our Security Audit Policy, Terms & Conditions and AI Use Policy. Nothing here overrides mandatory law or an express right in a signed agreement. The revision date identifies this version.

Ordinexis Sdn Bhd / Kuala Lumpur, Malaysia

Back to top