Sentrix

Security · Disclosure

Responsible vulnerability disclosure

How to report a vulnerability in sentrix.ca or app.sentrix.ca: scope, rules of engagement, response times and legal safe harbor for good-faith researchers.

Sentrix builds security and compliance software; we want to know when something is wrong with ours. This policy explains how to report a vulnerability affecting our website or our platform, what we commit to in return, and the protection you receive when you act in good faith. It follows ISO/IEC 29147 (disclosure) and ISO/IEC 30111 (handling), RFC 9116 (security.txt) and the coordinated vulnerability disclosure guidance published by CISA and its partners.

Scope

This policy covers the systems Sentrix operates directly:

SystemScope
sentrix.ca and www.sentrix.caPublic website, contact form, generated images and feeds
app.sentrix.caThe Sentrix platform: interface, API, integrations, authentication
Other *.sentrix.ca subdomainsIncluded when operated by Sentrix; when in doubt, ask before testing

Third-party services we rely on (hosting, email delivery, bot protection, analytics) are out of scope: report vulnerabilities that belong to them directly, or write to us and we will pass them on.

Rules of engagement

Your research is welcome when you follow these rules:

  • Test only with accounts you control; never try to reach another customer's account or data.
  • Stop at the proof of concept. Once a vulnerability is demonstrated, do not exploit it further: no data extraction, modification or destruction, no persistence, no lateral movement.
  • If you come across personal data or customer data, stop immediately, do not keep it, and tell us.
  • No denial of service, load testing, high-volume automated scanning, phishing, social engineering of our staff or customers, or physical intrusion.
  • Do not disclose anything publicly before the coordination described below is complete.
  • Do not make your report conditional on payment.

How to report

Write to security@sentrix.ca, in English or French. This address is reserved for security reports and is not routed through customer support. It is published in our security.txt file.

A good report contains:

  • the system and the URL or entry point concerned;
  • the type of vulnerability and its impact as you understand it;
  • step-by-step reproduction, with the requests or code needed;
  • screenshots, logs or other evidence supporting your analysis;
  • how you would like to be credited, or your preference for anonymity.

One report per vulnerability keeps tracking simple. Raw scanner output without a demonstrated impact is not considered a report.

Our commitments

StepTimeline
Acknowledgement2 business days
Triage and severity (CVSS 4.0)5 business days
Progress updateat least every 14 days
Fix for a critical vulnerability7 days
Fix for a high vulnerability30 days
Fix for a medium or low vulnerability90 days, or the next release cycle

We confirm the fix, ask whether you want to be credited, and tell you if a CVE identifier is requested.

Coordinated disclosure

We ask you to keep the report confidential until the fix ships or until ninety days after the report, whichever comes first. If a fix needs more time, we propose a reasoned extension; if no agreement is possible, you remain free to publish after that window, leaving out details that would expose our customers. We never ask for silence about the existence of a fixed vulnerability.

Safe harbor

When your research follows this policy, Sentrix considers it authorized and conducted in good faith. We will not bring civil action or a criminal complaint against you for that research, we will not enforce any clause of our terms of service that would forbid it, and if a third party takes action, we will make it known that you acted in accordance with this policy. This protection does not extend to third-party systems or to acts outside the rules above. If you are unsure whether a test is covered, ask us first.

Out of scope reports

The following are not followed up unless a concrete impact is demonstrated:

  • missing security headers or configuration judged suboptimal without a demonstrated exploit;
  • software version disclosure, banners or error messages without impact;
  • missing rate limits on non-sensitive forms, or self-XSS;
  • automated scanner output, issues specific to outdated browsers;
  • our third-party providers' practices, or vulnerabilities already reported and being fixed.

Recognition

We do not pay bounties at this time. With your consent, we thank you publicly when your report leads to a fix, and we name you in the related release notes if you wish.

References

  • ISO/IEC 29147:2018, Vulnerability disclosure, and ISO/IEC 30111:2019, Vulnerability handling processes.
  • RFC 9116, A File Format to Aid in Security Vulnerability Disclosure (security.txt).
  • CISA and partners, Coordinated Vulnerability Disclosure guidance for software manufacturers and online service providers (2026).

Frequently asked questions

Do you run a bug bounty?
Not at this time. This program is a coordinated disclosure policy: it sets out how to report a vulnerability to us, what we commit to in return and the protection good-faith researchers receive. With your consent, we publicly thank the people whose reports lead to a fix. If a bounty program is created, it will be announced on this page.
Can I test app.sentrix.ca with my organization's account?
No. Test only with accounts you control that hold no real customer data. If you are a customer and want a dedicated test environment, write to security@sentrix.ca before you start and we will tell you how to proceed. Any third-party data you come across during research must be left untouched and reported immediately.
What happens if you do not fix the issue within the deadlines?
We keep you informed of progress at least every fourteen days and explain any delay. If a fix needs more than the ninety-day coordinated disclosure window, we propose a reasoned extension. If no agreement is reached, you remain free to publish after that window, leaving out details that would expose our customers.
Can I write to you encrypted?
security@sentrix.ca accepts plain email. A public PGP key will be published on this page and in the Encryption field of our security.txt as soon as it is available. Until then, if your report contains especially sensitive data, send a summary without technical details first; we will then agree on a secure channel.

Let's talk about your compliance program.

Last updated: 2026-09-19