Responsible Testing Policy
Published by SOLVEX SPACE LTD. Version 1.0, effective 14 August 2026.
1. Authorization-first, always
No offensive security work — penetration testing, red teaming, phishing simulation, reverse engineering, or any adversary emulation — begins without signed written authorization from the owner of the target systems, a defined scope, and agreed rules of engagement. This applies to every one of our services, with no exceptions.
2. What we will not do
- Test, scan or investigate systems without proof of ownership or authority.
- Locate, track or profile private individuals.
- Provide access to another party's private data or accounts.
- Support unlawful activity in any jurisdiction, in any form.
3. How our free tools stay defensive
- Tools analyse assets you own or administer, or records that are lawfully public (DNS records, public chain data, published breach corpora, CVE databases).
- Recon-style tools use passive, public sources only and display an authorized-use notice you must accept.
- Inputs are stored hashed or aggregated — never as raw sensitive data about your infrastructure.
- All tools are rate-limited and monitored for abuse.
4. Adversary-perspective services
Services described as attacker-perspective advisory or adversary emulation replicate criminal tradecraft defensively, under contract, against systems whose owners commissioned the work — never against third parties.
5. Disclosure & findings
Vulnerabilities found during engagements are reported privately to the client. Aggregated, anonymized signals (for example, "a scanned host exposed an environment file") may appear in our public threat feed only when no target is identifiable.
6. Reporting a vulnerability in Solvex itself
This section is the target of the Policy field in our security.txt, and it is about our own platform — everything above concerns work we do for customers.
- Where to send it. security@solvex.space. That address, not the general contact address, so it reaches the people who can act on it.
- Scope. Anything Solvex runs: this site, the client and team portals, the free tools, the report verification service and our public APIs. Out of scope: third-party services we merely link to, and any system belonging to one of our customers.
- What we ask. Use only accounts and data that are yours. No denial-of-service, no load testing, no social engineering of our staff or customers, no automated scanning heavy enough to affect other users. If you reach someone else’s data, stop, do not save it, and tell us what you saw.
- What you get. We acknowledge reports within two business days and tell you what we intend to do about it within ten. If a fix takes longer than that, we will say so and keep you updated rather than going quiet.
- Safe harbour. If you follow the rules above and report to us promptly and privately, we will not pursue or support legal action against you for the research, and we will treat it as authorized. We cannot waive the rights of third parties.
- Credit. We are glad to credit you when the issue is fixed, or to keep your report anonymous — your choice. We do not currently run a paid bounty, and we will say so plainly rather than implying one.
7. Report abuse
Believe our platform or tools were used against your systems without authority? Contact contact@solvex.space — we investigate every report.