SECURITY

Security & disclosure policy

We break into things for a living, so we expect people to look closely at our own. If you find a security issue in our systems, here is how to tell us and what we promise in return.

Reporting an issue

Email [email protected] with enough detail to reproduce the issue: the affected asset, the steps, and the impact you observed. A short proof of concept helps. Our machine-readable contact is published at /.well-known/security.txt.

Our commitments to you

Scope

This policy covers assets we own and operate, primarily offensive.technology and its subdomains. Client systems from our engagements are never in scope here; they are governed by their own authorization and rules of engagement, and you must not test them.

Ground rules for good-faith research

To stay protected under this policy, please:

NO BOUNTY, STRAIGHT ANSWER We do not run a paid bug bounty program today. We will not pretend otherwise to attract reports. What we offer is a fast, honest response, a real fix, and credit where you want it. If that changes, this page will say so.

Safe harbor

We consider security research conducted in good faith and in line with this policy to be authorized. We will not treat it as a violation of our terms, and we will work with you rather than against you. If a third party brings action over research that followed this policy, we will make our authorization clear.