Overview
Responsible disclosure provides a professional process for reporting legitimate security concerns to Enigm. The disclosure model is designed to:- Support good-faith security research.
- Protect users while reports are assessed.
- Preserve confidentiality during validation and remediation.
- Encourage accurate technical reporting.
- Support coordinated security communication.
Security Research
Security researchers are encouraged to report legitimate security concerns. Good-faith security research contributes to platform resilience by helping identify vulnerabilities, unsafe behaviors, or security gaps before they can affect users. Research should be conducted responsibly and should avoid actions that disrupt services, access data without authorization, or expose other users to risk.Reporting Security Issues
Security issues should be reported through designated security reporting channels. Use the Security Contact page for current security communication details. Reports should include enough information to support review, such as:- Affected product or platform area.
- Description of the security concern.
- Potential impact.
- Safe reproduction information where appropriate.
- Relevant security context.
Disclosure Principles
Enigm responsible disclosure is guided by:- Good faith.
- Confidentiality.
- Accuracy.
- Responsible communication.
- User protection.
- Coordinated remediation.
- Operational safety.
Investigation Process
Reported issues are reviewed, assessed, and prioritized according to risk. Validated issues are tracked through remediation workflows. Assessment may consider impact, affected components, exploitability, user exposure, and available mitigations. Public documentation describes the process at a governance level.Coordinated Disclosure
Enigm supports coordinated disclosure practices intended to balance transparency and user protection. Coordinated disclosure may involve:- Report validation.
- Remediation planning.
- Security update preparation.
- Advisory or communication planning where appropriate.
- Timing that reduces user risk.
Good Faith Research
Good-faith research may include:- Security testing.
- Vulnerability identification.
- Security analysis.
- Responsible reporting.
Out-of-Scope Activities
The following activities are out of scope:- Service disruption.
- Social engineering.
- Privacy violations.
- Unauthorized data access.
- Physical attacks against personnel.
- Attempts to access, modify, or destroy data belonging to others.
- Extortion, coercion, or threats.
- Public disclosure before coordinated handling.