Security
Vulnerability disclosure policy
We welcome reports of security vulnerabilities in Autolycus systems. This policy explains what is in scope, how to report, and what you can expect from us.
Scope
What this policy covers
In scope
- autolycus.io and www.autolycus.io
Out of scope
- Our clients' systems. We test them only under contract, and this policy gives no permission to test them.
- Third-party services we use, such as our hosting and CDN providers
- Denial of service, spam, social engineering and physical attacks
- Automated scanner output with no demonstrated security impact
How to report
Send us the details
Email [email protected]. For sensitive details, please encrypt your message with our PGP key.
Key fingerprint: FD2D 472B 0B92 EE49 E6A9 E1E5 DAA4 66AE E28D F3C1
- What you found and where: the affected URL or component
- Steps to reproduce, including any proof-of-concept
- The impact you believe it has
- How to reach you, if you'd like us to follow up
Guidelines
Testing in good faith
- Test only in-scope systems, and cause as little impact as possible
- Don't access, change or delete data that isn't yours. Stop and report as soon as you've confirmed a vulnerability.
- Don't degrade our services or anyone else's
- Keep it confidential until the issue is fixed or we've agreed a disclosure date with you
Safe harbour
Our commitment to researchers
If you make a good-faith effort to follow this policy, we will consider your research authorised. We won't pursue or support legal action against you for it, and we'll work with you to understand and resolve the issue quickly.
What to expect
How we handle your report
- A response within 2 business days. This is guaranteed for every report.
- Updates as we investigate, and confirmation when the issue is resolved
- Anonymity. We don't publish researchers' names or credit reports publicly.
- No payment. We don't run a bug bounty or pay for reports.
Found something?
Email the details to [email protected]. You'll hear from us within 2 business days.