If you believe you've found a security issue in GxP-Desk, please tell us privately before disclosing it publicly. We investigate every report.
Email contact@seydel.consulting with a description of the issue, the steps to reproduce it, and any proof-of-concept material. Encrypting your report is not required, but if you prefer PGP, ask for a key in your first message and we will provide one.
Please include enough detail for us to reproduce the issue (affected URL or endpoint, request/response samples, and the impact you observed). Reports without reproduction steps take longer to triage.
In scope: the GxP-Desk application at gxpdesk.app and its subdomains, and the APIs those hosts serve.
Out of scope: denial-of-service testing, automated scanning that generates significant load, social engineering or phishing of GxP-Desk staff or customers, physical access attempts, and any testing against accounts or data you do not own or have explicit permission to test. Do not access, modify, or exfiltrate data belonging to other tenants — stop and report as soon as you can demonstrate impact.
We will not pursue legal action against researchers who make a good-faith effort to comply with this policy: report privately, avoid privacy violations and service disruption, and give us a reasonable opportunity to investigate and remediate before any public disclosure. This is not a bug bounty program — we do not offer monetary rewards, and we do not currently run a formal, continuous third-party penetration test program. We do take reports seriously and act on them.
We aim to acknowledge new reports within 3 business days and to give you a status update — triage outcome, severity, and expected next steps — within 10 business days. Timelines for a fix depend on severity and complexity; we will keep you informed as we work on it. We ask that you give us a reasonable window to remediate before any public disclosure, and we are happy to coordinate a disclosure timeline with you directly.