RESPONSIBLE DISCLOSURE

Vulnerability Disclosure Policy

Sextant (sextantquant.com) — version 1.1, in force since 28 September 2026 (version 1.0: 4 May 2026).

In short: if you discover a security vulnerability affecting Sextant, contact us at [email protected] (PGP optional on request). We acknowledge receipt within 72 h, investigate, and coordinate joint publication within 90 days maximum. No monetary reward at this stage, but systematic public recognition for valid reports.

1. Scope

In scope

Out of scope

2. Rules of engagement

3. How to report

Send your report to [email protected]. Request our PGP key if you wish to encrypt the report.

Recommended format

Subject: [VULN] <OWASP category> — <6-word summary>

1. Category (XSS, IDOR, SSRF, RCE, auth bypass, etc.)
2. Affected URL / endpoint
3. Reproduction steps (numbered, copyable)
4. Impact (what can an attacker concretely do?)
5. Proof of concept (screenshot, video, payload — without exfiltrating)
6. Suggested fix (optional)
7. Your public handle if you wish to be credited

4. Our response commitment

StepTarget delay
Acknowledgement of receipt72 hours (FR business days)
Initial triage + severity5 business days
Fix plan communicated2 weeks
Maximum embargo before publication90 days (negotiable if fix is complex)
Coordinated publication + creditafter fix deployment

5. Recognition

Sextant offers no monetary reward. However, any valid report leads to:

6. Safe harbor

We commit to not pursuing legal action against security researchers who:

  1. respect this policy in good faith,
  2. limit themselves to non-destructive testing techniques,
  3. only access data strictly necessary for demonstration,
  4. give us reasonable time to fix before publication.

If you have any doubt about the scope of this protection, contact us before your test at [email protected].

7. security.txt file

This policy is announced via the RFC 9116 standard at /.well-known/security.txt.