Security
XENLOOK welcomes good-faith security research on xenlook.com, xenlook.ai, xenlook.world, and our public product origins (on, game, c2pa, api, devhub). Report findings to [email protected]. This page is the Policy URL in security.txt.
If you act in good faith, avoid privacy harm, and stay within this policy, XENLOOK will not pursue legal action for the research itself. Do not extort, do not sell access, and do not publicly disclose before we have had a chance to fix.
Use your own accounts. Do not access other users' data. Stop if you hit production data you do not own. Rate-limit automated tests. Do not attack PKI, CA, or CRL availability.
We aim to acknowledge reports within 5 business days and to provide a status update within 14 days. Critical issues are prioritized. Credit is optional and listed on /security/acknowledgments after a fix ships, if you ask.