Vulnerability Reporting Policy

Revised · policies/VULN-REPORTING.md · 40d615a192f0

We welcome security research and report our findings in public.

Scope

  • Hosts within *.isotope13.(io|dev|ai|net)
  • Out of scope: issues customers wouldn't care about—spam, local clickjacking, weak SSL ciphers

Reporting

Open a public issue, or see our security.txt.

What to Expect

  • A response within 24 hours and a fix within 72
  • An invitation to co-write a blog article
  • $50 to the non-profit of your choice for a serious vulnerability with reproduction steps

Safe Harbor

We consider your research exempt from DMCA and CFAA prosecution and will not pursue legal action. Go crazy, but don't harm customers.