Finaxis Inc. protects the data our customers trust us with, and we welcome help from security researchers. This policy explains which systems you may test, how to test them responsibly, how to send us a report, what we commit to in return, and how long we ask you to wait before disclosing an issue publicly.
Security research carried out in line with this policy is authorized. We will work with you to understand and fix the problem quickly, and Finaxis will not recommend or pursue legal action against you for research conducted in accordance with it.
How to report a vulnerability
- Reporting email
- security@finaxis.ai
Email security@finaxis.ai. Reports may be submitted anonymously. The same address is published in our security.txt file.
To help us reproduce and fix the issue, please include:
- a description of the vulnerability and the class of issue you believe it is;
- where you found it: the URL, endpoint or component;
- the potential impact, as you understand it;
- steps to reproduce. Scripts, request logs and screenshots are welcome.
You may write to us in English or French.
Scope
Systems covered
https://finaxis.ai: the Finaxis website.https://app.finaxis.ai: the Finaxis application and the APIs it calls.
Out of scope
- The third-party services Finaxis is built on or connects to: accounting software, email, identity and cloud providers. A vulnerability in a third-party product should be reported to that vendor under its own policy.
- The status page, status.finaxis.ai, hosted by a third party.
- Any system not listed above. If you are unsure, email us before you begin.
What we ask of you
- Tell us as soon as possible after you discover a real or potential security issue.
- Give us a reasonable time to fix it before you disclose it publicly: at least 90 days from our acknowledgment.
- Make every effort to avoid privacy violations, degraded service, disruption to production systems, and destruction or alteration of data.
- Use an exploit only as far as needed to confirm that a vulnerability exists. Do not use it to access or exfiltrate data, to gain persistent access, or to pivot to other systems.
- If you confirm a vulnerability, or you encounter sensitive data (personal information, financial data, or anyone's business information), stop testing, tell us immediately, and keep the data strictly confidential.
- Test only against accounts you own or have explicit permission to use.
- Do not send a high volume of low-quality reports.
Testing that is not authorized
- Network or application denial-of-service testing (DoS or DDoS).
- Physical testing (office access, for example), social engineering (phishing or vishing) and any other non-technical testing.
- Testing of third-party services, as described under Scope.
What you can expect from us
- We acknowledge receipt of your report within 24 business hours.
- If you share a way to reach you, we keep you informed as we confirm the issue and work on a fix.
- We consider research conducted in accordance with this policy authorized, and we will not recommend or pursue legal action over it.
- We welcome a discussion of any concerns, and we are happy to credit you for your report if you would like.
- Finaxis does not currently run a bug bounty program and cannot offer a financial reward for reports.
Related policies
How we handle personal information is described in our privacy policy, and use of the platform is governed by our terms of use. Finaxis's security controls are detailed in our trust center.