Skip to Content
Developers / APIResponsible Disclosure

Responsible Disclosure

Version 1.0 · Effective from 1 September 2026 · Last reviewed 22 July 2026

Download PDF

We welcome reports from security researchers who find a vulnerability in our platform. This page explains how to report one safely.

1. How to report. Send details to [email protected]. Please include enough for us to reproduce the issue.

2. What we ask of you. Give us reasonable time to investigate and fix the issue before you disclose it publicly. Do not access, change or delete data that is not yours, do not degrade our service and do not go further than needed to show the issue.

3. What you can expect from us. We will acknowledge your report, keep you informed, and we will not take legal action against researchers who act in good faith and within this policy.

4. Scope. In scope: our own domains and applications — *.cashxchain.com, api.cashxchain.com, the iOS app, the Android app, and the web dashboard. Out of scope: third-party services we do not operate (report those directly to the relevant provider, e.g. Stripe, Coinbase, Cloudflare, AWS or Google); social-engineering against team members; physical attacks; denial-of-service (DoS/DDoS) testing; spam or phishing simulation; and findings that require an already-compromised account.