Responsible Disclosure Policy.
At AttackSurface, we respect and collaborate with the security research community. If you have discovered a vulnerability within our platform, we invite you to disclose it responsibly so we can remediate it promptly.
In-Scope Target Systems
* Note: Third-party services used for payment processing or transactional email are out of scope.
Legal Protection for Good-Faith Researchers
If you conduct vulnerability research in good faith and in compliance with this policy, we consider your activities authorized. We will not pursue civil action or initiate legal complaints against you regarding your research activities.
Researcher Guidelines
- Do not degrade platform availability: Denial-of-Service (DoS/DDoS) attacks, distributed flood testing, or resource exhaustion attacks are strictly prohibited.
- Protect user privacy: Never view, alter, extract, or delete data belonging to other user accounts. If a vulnerability reveals data belonging to another user, stop immediately and report.
- No social engineering: Phishing, vishing, or social engineering targeting AttackSurface staff or contractors is strictly prohibited.
- Coordinated disclosure: Give us reasonable time (up to 90 days) to address the vulnerability before discussing or publishing any details publicly.
How to Submit a Report
Please email your findings directly to our security intelligence team at:
• Initial Acknowledgement SLA: ≤ 24 Hours
• Triage Assessment SLA: ≤ 72 Hours
• Please include: Summary, step-by-step reproduction guide, and proof-of-concept.