generated: '2026-08-26' method: searched probe: true source: https://www.relexsolutions.com/policy/vulnerability-disclosure/ url: https://www.relexsolutions.com/policy/vulnerability-disclosure/ http_status: 200 program: published: true type: coordinated vulnerability disclosure policy bug_bounty: false bounty_platform: null paid: false contact: email: security@relexsolutions.com security_txt: false security_txt_note: >- RELEX serves no /.well-known/security.txt on any of its hosts — every probe returned 404 on www.relexsolutions.com and the API hosts, and the RELEX Identity hosts answer 200 with an HTML error shell rather than a document. The contact exists and is published, but only in prose on the policy page, so an automated scanner will not find it. This is the single cheapest fix available to RELEX in this whole profile. pgp: published: true fingerprint: 2642 CCF9 C58F F0CD 96EE 79B5 C845 2ACF BC0B 6187 location: public key servers scope: covered: all digital assets owned, operated or maintained by RELEX Solutions excluded: assets not owned by participating parties safe_harbor: published: true summary: >- RELEX states it "will not initiate or support legal action against you for accidental, good-faith violations of this policy", and will not pursue claims relating to circumvention of technical controls where the research complies with the policy. commitments: acknowledgement: prompt response committed, no stated SLA in hours or days progress_updates: committed remediation: 'committed "in a timely manner, within our operational constraints"' researcher_obligations: disclosure_embargo_days: 90 detail: Researchers must allow at least 90 days from the initial report before public disclosure. data_handling: access must be limited to the minimum required to demonstrate a proof of concept related: security_compliance: https://www.relexsolutions.com/security-compliance/ infosec_faq: https://www.relexsolutions.com/policy/infosec-faq/ privacy_trust_center: https://www.relexsolutions.com/privacy-trust-center/ ai_governance: https://www.relexsolutions.com/policy/ai-governance-trust-at-relex/ whistleblowing: https://www.relexsolutions.com/policy/whistleblowing-channel/ evidence: - source: https://www.relexsolutions.com/policy/vulnerability-disclosure/ status: 200 kind: disclosure policy page keywords: - vulnerability - security research - safe harbor - security@relexsolutions.com - PGP - source: https://www.relexsolutions.com/.well-known/security.txt status: 404 kind: absent