POLYMUX™
Security

Reporting a security issue

Last updated: 2026-10-07

Security reports about Polymux, polymux.io and synergygeeks.com are welcome. Send them to security@polymux.io. Polymux is pre-release software, built and run by one person at Synergy Geeks LLC, and the timelines below reflect that.

What is in scope

  • polymux.io and its status feed.
  • synergygeeks.com and its contact form (the /api/contact endpoint).
  • The Polymux software, once design-partner deployments begin. There is no public download yet. A report from a design partner follows the same process.

Out of scope:

  • Third-party services the sites depend on, such as Cloudflare and Resend. Reports about those go to the vendor.
  • Denial-of-service testing, and spam or load generation against the contact form.
  • Social engineering of the owner, physical access, and attacks that need an already-compromised device.
  • Automated scanner output with no demonstrated impact, and missing headers or settings with no exploit.

How to report

Email security@polymux.io with:

  • what was found and where: the URL, endpoint or component, and the version if known
  • steps to reproduce
  • the impact as understood
  • a proof of concept, if there is one

No PGP key is published yet. A report that needs a secure channel can start with a short message asking for one.

What to expect

These are targets. One person handles every report, so travel or illness can slow a reply.

  • Acknowledgement within 5 business days.
  • An initial assessment within 10 business days.
  • A fix or mitigation date agreed with the reporter. The default disclosure window is 90 days from the report. It is shorter when a fix ships sooner, and it can be extended by agreement.

There is no bounty program and no payment. Reporters are credited in the public note on request.

Good-faith research

Research that follows these rules is welcome, and is considered authorized under this policy:

  • Test only against accounts and data the researcher owns or has permission to use.
  • Stop and report when someone else's personal data comes into view. Access no more than needed to show that the issue exists.
  • No actions that degrade the service for others, no persistence, and no modification or deletion of data.
  • Allow a reasonable time for a fix before publishing details.

This policy covers the systems listed above. It does not authorize testing of third-party systems, and it cannot waive anyone else's rights.

How reports are handled

Reports go to one mailbox and are read by one person. Details are shared outside the company only with the reporter's agreement, for example with a vendor whose product is involved.