Skip to content
FOR RESEARCH USE ONLY · NOT FOR HUMAN OR VETERINARY USE
X Factor PeptidesX FACTORLEGAL All policies
← Legal Center

Responsible Disclosure & Security Policy

X Factor Research LLC (DBA X Factor Peptides) takes the security of our customers, our systems, and the integrity of our supply chain seriously. This document describes how to report a vulnerability and what to expect from us in return.

Scope

In scope:

Out of scope:

How to report

Email: [email protected]

Include:

  1. A clear description of the issue
  2. Steps to reproduce
  3. Impact assessment from your point of view
  4. Any proof-of-concept code or screenshots (please redact PII)
  5. Your name or handle for credit (optional)

We accept reports in English. PGP key: published at /.well-known/pgp.txt (rotating annually).

What to expect

Severity tiers

TierExamplesTarget fix
CriticalRCE, auth bypass on admin, payment manipulation, mass PII exposure72 hours
HighStored XSS in admin, IDOR exposing other customers' orders, RLS bypass14 days
MediumReflected XSS, open redirect, missing CSRF on non-state-changing endpoint30 days
LowInformation disclosure, missing security header, weak CSP rule90 days or batched

Safe-harbor

We will not pursue legal action against researchers who:

This safe-harbor extends only to actions covered by this policy and does not waive any rights of third parties.

Out-of-band

If you cannot reach us by email, use the form at https://www.xfactorpeptidelab.com/contact and mark it [SECURITY]. As a last resort: [email protected].

Last updated: 2026-06-03.