Responsible Disclosure
How security researchers can report potential vulnerabilities affecting Fintech Galaxy's public services.
Report safely
If you believe you found a security vulnerability affecting a Fintech Galaxy public service, provide a clear description, affected asset, reproducible steps, potential impact, and safe supporting evidence through the security contact route.
Protect customers and systems
Do not access customer data, perform denial of service testing, degrade a service, use social engineering, exfiltrate information, change records, or test third party systems without their written authorization.
Handling a report
Fintech Galaxy will route the report to the appropriate security owner, acknowledge valid submissions when contact information is provided, investigate in good faith, and coordinate communication based on risk and remediation needs.
No secrets in forms
Do not send passwords, private keys, access tokens, banking credentials, or unnecessary personal data. If sensitive transfer is necessary, first request an approved secure channel.