Version: 1.0
Effective Date: 20.08.2026
Last Updated: 20.08.2026
MAXPRIMACY takes the security of its website, information and digital systems seriously.
We appreciate responsible reports from security researchers, technology professionals and other individuals who identify a potential security vulnerability affecting MAXPRIMACY.
This Responsible Disclosure Policy explains how to report a suspected vulnerability and establishes reasonable boundaries for good-faith security research.
1. How to Report a Vulnerability
If you believe you have identified a security vulnerability affecting MAXPRIMACY, please contact:
Please include enough information for us to understand and reproduce the issue where reasonably possible.
A useful report may include:
- a clear description of the suspected vulnerability;
- the affected URL, page, endpoint or functionality;
- steps required to reproduce the issue;
- screenshots or other supporting evidence;
- the potential security impact;
- any conditions required for exploitation;
- suggested remediation, if you have one;
- your contact information if you would like us to follow up.
Please do not include unnecessary personal data, credentials, confidential third-party information or copies of data obtained from other users.
If sensitive evidence must be shared, contact us first so that an appropriate transmission method can be agreed.
2. Scope
Unless MAXPRIMACY expressly confirms otherwise in writing, this policy applies only to:
and public-facing website functionality directly controlled by MAXPRIMACY.
The inclusion of the website in scope does not authorise unrestricted penetration testing or access to non-public systems.
3. Out of Scope
Unless expressly authorised in writing, the following are outside the scope of this policy:
- systems, infrastructure or services operated by third parties;
- hosting-provider infrastructure not controlled by MAXPRIMACY;
- email-provider infrastructure;
- social media platforms;
- payment, banking or electronic-signature providers;
- analytics, cloud, AI or SaaS platforms operated by third parties;
- client systems or client data;
- non-public storage systems;
- administrative infrastructure not intentionally exposed for public use;
- employee or contractor devices;
- physical premises or physical security systems.
If you discover an issue affecting a third-party system used by MAXPRIMACY, please report it to the relevant provider unless the issue arises specifically from MAXPRIMACY’s configuration or implementation.
4. Good-Faith Security Research
We welcome research intended to identify and help correct genuine security vulnerabilities.
Testing should be limited to the minimum activity reasonably necessary to confirm that a vulnerability exists and understand its potential impact.
If you encounter personal data, confidential information, credentials or other information that you were not intended to access:
- stop accessing the information;
- do not copy or retain more than is strictly necessary to demonstrate the issue;
- do not disclose the information to others;
- notify MAXPRIMACY promptly.
Good-faith vulnerability research generally means research conducted to improve security rather than to cause harm, obtain an improper commercial advantage, extort a payment or exploit affected users.
This approach is consistent with widely used vulnerability-disclosure guidance, which emphasises minimal testing, avoiding harm and promptly reporting vulnerabilities.
5. Prohibited Activities
This policy does not authorise:
- denial-of-service or distributed denial-of-service attacks;
- intentional service disruption or degradation;
- malware deployment;
- ransomware;
- destructive testing;
- deletion, corruption or modification of data;
- credential stuffing;
- password spraying;
- brute-force attacks beyond minimal testing specifically required to demonstrate an issue;
- phishing;
- social engineering;
- impersonation;
- physical attacks;
- accessing accounts belonging to other users;
- persistence in MAXPRIMACY systems;
- lateral movement between systems;
- privilege escalation beyond what is minimally necessary to demonstrate a vulnerability;
- downloading, extracting or retaining datasets;
- testing third-party systems without their permission;
- accessing client information;
- using a vulnerability for commercial exploitation, extortion or coercion.
Do not continue testing after the security issue has been demonstrated if further activity would increase risk or exposure.
6. Automated Scanning
Reasonable, non-disruptive automated security scanning may be used against in-scope public-facing website functionality provided that it:
- does not materially affect service availability;
- does not generate excessive traffic;
- does not attempt destructive exploitation;
- does not access unrelated data;
- respects reasonable technical rate limits.
Large-scale scanning, aggressive fuzzing, load testing or activity that may degrade service requires prior written authorisation.
7. What You Can Expect From MAXPRIMACY
For reports submitted in accordance with this policy, MAXPRIMACY will aim to:
- acknowledge receipt within a reasonable period, normally within 5 Business Days;
- review the report in good faith;
- request additional information if necessary;
- assess the potential impact;
- take proportionate remediation measures where the issue is confirmed;
- communicate material progress where reasonably appropriate.
The complexity and priority of security issues vary, so we do not guarantee a specific remediation deadline.
Critical vulnerabilities may receive priority over lower-risk findings.
8. Safe Harbour for Good-Faith Research
Where security research is conducted in good faith, remains within the scope of this policy and complies with the restrictions above, MAXPRIMACY does not intend to initiate legal action solely because of that authorised research.
This statement applies only to actions that MAXPRIMACY itself is legally entitled to authorise.
It does not:
- create immunity from applicable law;
- bind law-enforcement or regulatory authorities;
- authorise access to third-party systems;
- waive the rights of third parties;
- protect activity conducted for malicious, fraudulent, coercive or extortionate purposes.
If you are unsure whether a proposed activity is permitted, contact security@maxprimacy.com before proceeding.
9. Responsible and Coordinated Disclosure
Please give MAXPRIMACY a reasonable opportunity to investigate and address a reported vulnerability before publicly disclosing technical details that could increase security risk.
We may discuss an appropriate disclosure timeline with the reporter depending on:
- severity;
- complexity;
- affected systems;
- availability of a remediation;
- risk to users or third parties.
Nothing in this section is intended to prevent disclosures required by law.
10. Security Research Recognition
MAXPRIMACY may, at its discretion and with the researcher’s consent, publicly acknowledge a person who has responsibly reported a valid vulnerability.
Recognition is not guaranteed.
A researcher may also request to remain anonymous.
11. No Bug Bounty Commitment
This Responsible Disclosure Policy is not a bug bounty programme.
Submission of a vulnerability report does not create:
- a right to payment;
- a right to compensation;
- a contractual relationship;
- an employment or contractor relationship;
- an obligation for MAXPRIMACY to purchase services.
MAXPRIMACY may choose to recognise exceptional contributions at its sole discretion, but no reward should be assumed unless expressly agreed in writing in advance.
12. Privacy
Personal data submitted as part of a vulnerability report will be processed for purposes such as:
- receiving and assessing the report;
- communicating with the reporter;
- investigating the issue;
- maintaining appropriate security records;
- establishing, exercising or defending legal rights where necessary.
For more information, see the MAXPRIMACY Privacy Notice:
https://maxprimacy.com/legal/privacy/
13. Confidentiality
Information provided by MAXPRIMACY during investigation of a security report may itself be confidential.
Unless agreed otherwise, a reporter should not publish confidential remediation information, credentials, private system details, personal data or information concerning third parties.
14. Changes to This Policy
MAXPRIMACY may update this Responsible Disclosure Policy to reflect:
- changes to its systems;
- security practices;
- legal requirements;
- vulnerability-disclosure processes.
The current version and effective date will be published on this page.
15. Contact
Security vulnerability reports:
General enquiries:
Website:
LIMITED LIABILITY COMPANY “MAXPRIMACY”
Registration No. / EDRPOU: 46371303
Ukraine
