generated: '2026-08-05' method: searched probe: true source: https://www.11x.ai/security/disclosure policy: - https://www.11x.ai/security/disclosure contact: - mailto:security@11x.ai program: name: 11x Responsible Disclosure & Bug Bounty Policy type: self-hosted platform: null rewards: true reward_range: >- USD 100 to several thousand, discretionary, scaled by severity, impact, exploitability and report quality. safe_harbor: true hall_of_fame: true first_reporter_only: true sla: acknowledgement: 2 business days status_update: 10 business days disclosure_window: 90 days before public disclosure scope: in: - '*.11x.ai (web properties and APIs)' - Alice and Julian applications and associated customer dashboards - authentication and authorization flaws - data isolation and multi-tenant boundary issues - vulnerabilities exposing customer data or enabling account takeover out: - denial-of-service, volumetric or load testing - social engineering of employees, customers or vendors - physical attacks or attacks requiring physical device access - third-party service issues without demonstrated impact on 11x systems - automated scanner findings without demonstrated impact - missing security headers or cookie flags without demonstrable impact - rate-limiting issues without demonstrated abuse impact - self-XSS or issues requiring an already-compromised browser - email spoofing / SPF-DKIM-DMARC issues without an exploitable path evidence: - source: well-known/11x-security.txt kind: security.txt fields: [Contact, Expires, Canonical, Preferred-Languages, Policy] - source: https://www.11x.ai/security/disclosure kind: disclosure-policy http_status: 200 note: >- 301-redirects to a Webflow-hosted plain-text asset under cdn.prod.website-files.com, which is where the full policy text is actually served. - source: https://trust.11x.ai/ kind: trust-center-disclosure-invitation x-evidence: fetched: '2026-08-05' security_txt_expires: '2027-04-24T00:00:00Z'