SECURITY
Security & disclosure policy
We break into things for a living, so we expect people to look closely at our own. If you find a security issue in our systems, here is how to tell us and what we promise in return.
Reporting an issue
Email [email protected] with enough detail to reproduce the issue: the affected asset, the steps, and the impact you observed. A short proof of concept helps. Our machine-readable contact is published at /.well-known/security.txt.
Our commitments to you
- We will acknowledge your report within three business days.
- We will keep you updated as we investigate and work toward a fix.
- We will not pursue or support legal action against you for good-faith research that follows this policy.
- With your permission, we are glad to credit you once the issue is resolved.
Scope
This policy covers assets we own and operate, primarily offensive.technology and its subdomains. Client systems from our engagements are never in scope here; they are governed by their own authorization and rules of engagement, and you must not test them.
Ground rules for good-faith research
To stay protected under this policy, please:
- Stay within the scope above, and stop as soon as you confirm a vulnerability.
- Do not access, modify, or delete data that is not yours. Use test accounts and minimal proof.
- Do not degrade our service. No denial-of-service, no automated high-volume scanning that disrupts availability.
- Do not social-engineer our people or third parties, and do not target physical facilities.
- Give us a reasonable chance to fix the issue before disclosing it publicly, and coordinate timing with us.
Safe harbor
We consider security research conducted in good faith and in line with this policy to be authorized. We will not treat it as a violation of our terms, and we will work with you rather than against you. If a third party brings action over research that followed this policy, we will make our authorization clear.