Security research

Bug bounty & responsible disclosure

Xtrm runs a managed bug bounty program and follows responsible disclosure — researchers are credited when an issue is identified and mitigated.

Report confidentially to vulnerability@xtrm.com or submit through the managed program portal. Findings are triaged by the security team, and fixes are verified before disclosure.

How do I report a vulnerability?

  1. 1

    Submit

    Via the portal, or email vulnerability@xtrm.com.

  2. 2

    Receipt confirmed

    The security team acknowledges your report.

  3. 3

    Triage & mitigation

    Impact assessed; fix deployed and verified.

  4. 4

    Credit

    Researchers are credited for identified issues.