public utility
Security
Security Policy
How to report security issues on the Plexo Institute public site, the boundaries for responsible testing, and how reports are handled and acknowledged.
Page Scope
Security Policy is a legal prose page in the public utility surface. How to report security issues on the Plexo Institute public site, the boundaries for responsible testing, and how reports are handled and acknowledged.
Purpose and scope
This Security Policy explains how to report suspected security issues affecting public Plexo Institute pages and related public-site behavior.
The policy does not authorize testing of non-public systems, third-party providers, non-public partner workflows, internal routes, production infrastructure, or user accounts without written permission. Last updated: May 29, 2026.
How to report an issue
Security reports can be sent to [email protected] with the subject line "Security report". Include the affected URL, a concise description, steps to reproduce, impact, screenshots or logs where helpful, and your contact information.
Do not include secrets, personal data, third-party confidential data, or exploit payloads beyond what is necessary to understand the issue.
Responsible testing rules
Do not perform destructive testing, denial-of-service testing, spam, phishing, social engineering, or physical attacks.
Do not access, alter, delete, exfiltrate, or publish data that is not yours.
Do not bypass authentication, rate limits, or access controls beyond the minimum needed for a safe proof of concept.
Do not test third-party services, accounts, or infrastructure unless Plexo has explicitly authorized that scope in writing.
What to expect
Plexo will review credible reports and may contact you for more information. Response timing depends on severity, reproducibility, affected systems, and operational availability.
Unless Plexo agrees in writing, there is no public bug bounty, reward, compensation program, or permission to disclose an issue publicly before Plexo has had a reasonable opportunity to investigate and remediate it.
Security limitations
Plexo uses reasonable administrative, technical, and organizational safeguards, but no website, network, or data transmission is perfectly secure.
If you believe your interaction with Plexo Institute exposed personal information or account data, contact [email protected].
Related Pages
Route Context
This crawlable route snapshot gives search engines and language models a stable public description of the Security Policy page before client-side navigation loads. Its canonical route is /legal/security, its surface family is public utility, and its page role is legal prose. The page is connected to adjacent public Institute surfaces including Plexo Institute, Legal Center, About Plexo Institute, Data Methodology — How Plexo Institute Tracks Registry Data, Terms of Use, so crawlers can understand where this route sits in the Plexo knowledge graph. The publication contract records the current readiness state as fallback review and keeps the route held until an explicit opening approval changes the robots and sitemap policy.
Publication Contract
- Canonical route
- /legal/security
- Surface
- public utility
- Readiness
- fallback review
- Generated at
- 2026-08-28T17:26:38.963Z