Responsible Disclosure

Security vulnerabilities should be reported privately to protect all users.

Why Responsible Disclosure?

Security vulnerabilities are a critical concern for any organization. At ShadowEyes, we take security seriously and appreciate the responsible disclosure of security vulnerabilities by the security research community. Responsible disclosure allows us to address vulnerabilities before they can be exploited, protecting our users and systems.

What to Report

Please report the following types of security issues:

  • Authentication and authorization vulnerabilities
  • Data encryption and protection flaws
  • SQL injection and code injection vulnerabilities
  • Cross-site scripting (XSS) and CSRF vulnerabilities
  • Insecure API endpoints or data exposure
  • Infrastructure and server misconfigurations
  • Privacy violations or data handling issues

What NOT to Report

Please do not report the following:

  • Vulnerabilities in third-party services or libraries
  • Social engineering or phishing attacks
  • Physical security issues
  • Issues requiring physical access to our infrastructure
  • Spam or non-security related issues

How to Report a Vulnerability

To report a security vulnerability, please use our anonymous contact form and mark your subject as "Security Disclosure". Include:

  • A clear and detailed description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact and risk assessment
  • Proof of concept (if applicable)
  • Your preferred method of contact (if you choose to identify yourself)

Your anonymity is fully protected. You can also remain anonymous if you prefer.

Report a Vulnerability

Disclosure Timeline

We follow a coordinated disclosure timeline:

Day 1-3: Initial Assessment

We review your report and assess the vulnerability's severity and scope.

Day 4-14: Fix Development

Our security team works to develop and test a fix for the vulnerability.

Day 15-30: Patch Release

We release a security patch to our users and publicly acknowledge the fix.

Day 31+: Publication

We may publish details about the vulnerability after it has been patched.

Our Commitment

  • We will acknowledge receipt of your vulnerability report within 3 days
  • We will keep you informed of our progress in addressing the vulnerability
  • We will not take legal action against researchers who follow this policy
  • We will acknowledge your contribution in security advisories (with your permission)
  • We maintain your anonymity if you request it

Questions?

If you have questions about this responsible disclosure policy, use our anonymous contact form.

Send Anonymous Message