Vulnerability Reporting Policy
We welcome security research and report our findings in public.
Scope
- Hosts within
*.isotope13.(io|dev|ai|net) - Out of scope: issues customers wouldn't care about—spam, local clickjacking, weak SSL ciphers
Reporting
Open a public issue, or see our security.txt.
What to Expect
- A response within 24 hours and a fix within 72
- An invitation to co-write a blog article
- $50 to the non-profit of your choice for a serious vulnerability with reproduction steps
Safe Harbor
We consider your research exempt from DMCA and CFAA prosecution and will not pursue legal action. Go crazy, but don't harm customers.