← Back

Report a Vulnerability

Last updated: July 1, 2026

We are grateful to the researchers who help us keep the Services safe. This page explains how to report a vulnerability and what you can expect from us in return.

1. How to report

Email a clear description to security@intuitum.xyz — it reaches a monitored inbox and accepts mail from anyone, no account needed. Include the affected component, the steps to reproduce, and the impact you observed. If you need to share sensitive details, ask us for a key and we will send one.

2. Safe harbor

We will not pursue or support legal action against researchers who act in good faith, follow this policy, avoid privacy violations and service disruption, and give us reasonable time to respond before disclosing publicly.

3. In scope

Vulnerabilities in intuitum.xyz, Diffuse, Solo, and the systems we operate. Please focus on issues that affect the confidentiality, integrity, or availability of the Services or the data they hold.

4. Out of scope

Denial-of-service testing, social engineering of our staff or users, physical attacks, and any finding that requires access to an account or device that is not yours. Reports from automated scanners without a demonstrated impact are unlikely to qualify.

5. What to expect

We will acknowledge your report within five business days, keep you updated as we investigate, and let you know when the issue is resolved. With your permission, we are glad to credit your contribution.

Questions about this document? Contact us.