← Back to Xopoz
⚑ White Hat Policy

Security researchers are welcome — but you must ask first.

Xopoz is an encrypted GPS platform that handles sensitive location data for real users. We invite ethical hackers to help us harden it, under written authorisation only. In exchange, we offer a meaningful reward.

Overview

This page sets out the rules for security research against Xopoz infrastructure, mobile clients, and APIs. It exists to protect three things: our users' data, the integrity of the Xopoz service, and you — the researcher — from legal exposure.

1 · Prior Written Authorisation Is Mandatory

You must contact us and receive written authorisation BEFORE any testing. Probing, scanning, fuzzing, intercepting, or attempting to exploit Xopoz endpoints, the Android client, or related infrastructure without prior written agreement is not permitted and will be treated as a hostile act under applicable computer-misuse and data-protection laws.

To request authorisation, send an email to xopoz@tiritix.com with the subject "White Hat Authorisation Request". Include:

We aim to respond within five working days. Authorisation, when granted, is delivered in writing, names the authorised researcher, fixes the scope, the test window, and the rules of engagement.

Request Authorisation

2 · Reward — One Free Year of Xopoz

Each verified vulnerability earns you one free year of Xopoz use — a personal team subscription, valid for twelve months from the date the fix ships.

The reward is granted when, after responsible disclosure, the report meets all of the following:

Multiple distinct vulnerabilities reported in the same engagement stack: each verified finding adds another year, up to a sensible maximum we will discuss with you.

3 · In-Scope Targets

Once authorisation is granted, the following are typically in scope (subject to the specific authorisation letter):

4 · Out of Scope

The following are explicitly out of scope and will not earn a reward, even with authorisation:

5 · Rules of Engagement

6 · Safe Harbour

For researchers who hold valid prior written authorisation and stay within its scope and rules, TIRITIX commits to:

Researchers acting outside this policy — including testing without prior authorisation — receive no safe harbour and may be reported to the relevant authorities.

7 · Contact

All correspondence relating to this policy goes to xopoz@tiritix.com. PGP-encrypted reports are encouraged; ask for the current public key in your first message.

Contact xopoz@tiritix.com