Last updated: August 12, 2026
ESXPress takes the security of our platform and our customers' data seriously. We welcome security researchers to report vulnerabilities they discover, and we are committed to working with the research community to verify, triage, and remediate legitimate findings. This page explains how to report a vulnerability, what we commit to once you do, and what falls within the scope of this program.
Please email your findings to [email protected]. To help us triage quickly, include as much of the following as possible:
Third-party services used by ESXPress (e.g., Stripe, Supabase, Cloudflare) maintain their own disclosure programs and are out of scope for this policy.
The following activities are not authorized and are outside the scope of this policy:
If you are unsure whether an activity is in scope, ask us first at [email protected] before you begin.