Sextant (sextantquant.com) — version 1.1, in force since 28 September 2026 (version 1.0: 4 May 2026).
In short: if you discover a security vulnerability affecting Sextant, contact us at [email protected] (PGP optional on request). We acknowledge receipt within 72 h, investigate, and coordinate joint publication within 90 days maximum. No monetary reward at this stage, but systematic public recognition for valid reports.
https://www.sextantquant.com and https://sextantquant.com (frontend, public pages, authenticated dashboard)https://api.sextantquant.com (API: audit request form, sign-up from the Mirror, payment)Send your report to [email protected]. Request our PGP key if you wish to encrypt the report.
Subject: [VULN] <OWASP category> — <6-word summary> 1. Category (XSS, IDOR, SSRF, RCE, auth bypass, etc.) 2. Affected URL / endpoint 3. Reproduction steps (numbered, copyable) 4. Impact (what can an attacker concretely do?) 5. Proof of concept (screenshot, video, payload — without exfiltrating) 6. Suggested fix (optional) 7. Your public handle if you wish to be credited
| Step | Target delay |
|---|---|
| Acknowledgement of receipt | 72 hours (FR business days) |
| Initial triage + severity | 5 business days |
| Fix plan communicated | 2 weeks |
| Maximum embargo before publication | 90 days (negotiable if fix is complex) |
| Coordinated publication + credit | after fix deployment |
Sextant offers no monetary reward. However, any valid report leads to:
We commit to not pursuing legal action against security researchers who:
If you have any doubt about the scope of this protection, contact us before your test at [email protected].
This policy is announced via the RFC 9116 standard at /.well-known/security.txt.