XIXOIO · LEGAL
Reporting security vulnerabilities
Version 1.5 · effective from 1 September 2026
Where to report
info@xixoio.com, with a subject line beginning SECURITY. We read reports and acknowledge receipt.
What to include
Where you found it, how to reproduce it, what impact you think it has, and how to reach you. Plain prose is fine; we have no form for this and do not want one.
How we handle it
We acknowledge receipt without undue delay. We verify the finding and tell you whether we accept it. We inform you when a fix is deployed. Publication is agreed with you, not against you.
In scope
This website and its publicly accessible parts.
Out of scope
The infrastructure of the suppliers on which the website runs, third-party websites linked from here, and services operated by other entities of the group. Report those to their operators; we are happy to point you to the right place.
What not to do while testing
Do not interfere with data that is not yours. Do not attempt denial of service or load testing. Do not use social engineering against people. Do not download or publish anyone's personal data — if you encounter it, stop and write to us. Do not use a finding as leverage or demand payment in exchange for silence.
Our commitment
If you follow these rules and act in good faith, we will not take legal action against you for the report itself. This commitment does not cover conduct that breaks the rules.
Rewards
We do not run a bounty programme. We say thank you and, with your consent, credit you by name in the record of the fix.
Genesis One OS is a concept and a target architecture. Individual parts exist and work; the whole is not in production. It is not presented as licensed or regulator-approved financial infrastructure. The content of this website is informational and does not constitute an investment offer, nor investment, legal, tax or financial advice.
Submitting an application, registering, expressing interest, starting a conversation, taking part in a demonstration, due diligence, a pilot or any other assessment, and any confirmation of receipt or preliminary approval thereof, do not create a contract, a binding promise or any legal entitlement to a licence, access, participation, continued negotiations or the establishment of a business relationship.
Every applicant may, to an extent proportionate to the nature of the intended relationship, be subject to assessment of identity and ownership structure, trustworthiness and integrity, source of funds, sanctions and regulatory status, and security, technical and risk profile, and may be asked to provide or update information.
The relevant legal person identified for the given module or service may, to the maximum extent permitted by law, refuse an application and may restrict, suspend or terminate access, registration, a pilot, a licence or any other participation that is not provided under an already concluded contract, based on its own legal, regulatory, sanctions, security, technical, capacity, integrity, reputational, strategic or operational assessment, including after preliminary approval. It need not state a reason unless required otherwise by law, by a decision of a competent authority or by an effective contract.
An automated confirmation, a status shown in an interface, or a statement or output of an AI or agent does not constitute an offer, an acceptance of an offer or a binding declaration on behalf of any legal person. Where a contractual relationship has already been concluded, the conditions and consequences of its restriction, suspension or termination are governed by the relevant contract and by binding law; the contract prevails over this notice. Rights and liabilities that cannot be excluded by law remain unaffected.