generated: '2026-09-02' method: searched probe: true source: https://x-tention.com/en/responsible-disclosure name: x-tention Responsible Disclosure program: type: responsible-disclosure bug_bounty: false bounty_platform: null policy_url: https://x-tention.com/en/responsible-disclosure scope_statement: >- Any security-relevant issue or vulnerability in x-tention group systems, networks, software or services. The policy is stated at group level and does not enumerate individual in-scope hosts. contact: email: vulnerability@x-tention.at email_source: >- Published on the Responsible Disclosure page as a ROT13-obfuscated `data-mail-to` attribute (ihyarenovyvgl/ng/k-gragvba/qbg/ng), decoded here; the page renders it behind a "Click to view email" control rather than as plain text. encrypted_reporting: >- Offered on request — reporters are asked to contact the address in advance to arrange encrypted transmission. No PGP key is published. response_commitment: acknowledgement: 48 hours progress_updates: regular, until the issue is resolved safe_harbor: >- Stated. "Provided that you comply with the instructions above, no legal action will be taken against you." reporter_credit: >- On explicit request, the reporter is named as discoverer in public communication. confidentiality: >- Reports treated as confidential; no personal information shared with third parties. reporter_obligations: - Provide enough information to reproduce (typically the IP address or URL of the affected system plus a description). - Do not exploit the vulnerability by downloading, manipulating or deleting data; delete any confidential data obtained accidentally. - Do not disclose to third parties before remediation. - No physical-security attacks, social engineering, or DDoS. basis: >- The policy states it is based on the Responsible Disclosure Guideline of the Dutch National Cyber Security Centre, written by Floor Terra (https://www.responsibledisclosure.nl/en/). security_txt: published: false note: >- No /.well-known/security.txt is served. https://x-tention.com/.well-known/security.txt returned 404 and https://mach.health/.well-known/security.txt returned 404 on 2026-09-02. The disclosure policy exists only as an HTML page, so an automated RFC 9116 consumer cannot find the reporting address. evidence: - source: https://x-tention.com/en/responsible-disclosure http_status: 200 kind: disclosure page fetched: '2026-09-02' keywords: - vulnerability - responsible disclosure - no legal action - 48 hours - source: https://x-tention.com/.well-known/security.txt http_status: 404 kind: negative probe fetched: '2026-09-02' - source: https://mach.health/.well-known/security.txt http_status: 404 kind: negative probe fetched: '2026-09-02'