This website information is provided for general informational purposes and should be reviewed with qualified legal counsel for jurisdiction-specific requirements.
Scope
This page applies to the security of the ExcelyTech marketing website at https://excelytech.com and related public web infrastructure operated to deliver that Site (for example, hosting and content delivery used for these pages).
It does not describe the security posture of managed Backup & Restore, Disaster Recovery (DRaaS), Endpoint Security, or SaaS Backup services delivered to customers under separate agreements. Reports about customer environments, production systems, or non-public applications should use channels agreed with ExcelyTech for support or security operations—not this page alone.
Nothing on this page constitutes a guarantee that the Site is free from vulnerabilities or that any particular security control is in place company-wide.
How to report
Send a detailed report to info@excelytech.com. Include:
- A clear description of the issue and the potential impact;
- Steps to reproduce, proof-of-concept if available, and affected URLs or components;
- The date you discovered the issue and whether it is still exploitable;
- Your contact information so we can follow up if needed.
Please encrypt sensitive details if your mail client supports it, or ask us for a preferred secure channel when you initiate contact.
Good-faith research expectations
When investigating the Site, we ask that you:
- Act in good faith and avoid privacy violations, destruction of data, or service disruption;
- Do not access, modify, or exfiltrate data that is not yours;
- Do not perform denial-of-service testing or automated scanning at high volume without prior written approval;
- Give us reasonable time to investigate and remediate before public disclosure;
- Comply with applicable laws.
We may take legal action if research is not conducted in good faith or causes harm, but we will not pursue legal action against researchers who comply with this page and applicable law when reporting issues in the Site scope.
Out of scope
Reports that typically fall outside this program include, without limitation:
- Social engineering or phishing against ExcelyTech personnel;
- Physical security issues unrelated to the Site;
- Issues in third-party services not operated for this Site, except where they directly and materially affect Site visitors;
- Missing security headers or cookie flags without demonstrated exploitability;
- Spam or content quality issues unrelated to security.
Our response
We will acknowledge receipt of credible reports when practicable and investigate issues within the Site scope. Timelines depend on severity and complexity. We may request additional information and will notify you when we believe an issue is resolved, subject to legal and operational constraints.
Recognition and rewards
ExcelyTech does not operate a public bug bounty or monetary reward program for this Site. We appreciate responsible disclosure and may acknowledge your contribution with your permission after a fix is deployed.
Safe harbor
If you comply with this page and applicable law in your testing and reporting, ExcelyTech will consider your research authorized for purposes of the Site scope and will not initiate legal action against you solely for such activity.
Other contact
Non-security website questions may be sent to info@excelytech.com. Privacy-related requests should use info@excelytech.com.