We're a small team running a DNS filter for security professionals. Honest researchers find honest bugs — and we'd rather hear them from you than read about them in a post-mortem.
PGP key for sensitive details: fingerprint 0xABCD1234… (full key on request — we'll publish on /security/pgp once SOC 2 audit confirms our key-rotation cadence).
Include in your report:
Anything that meaningfully degrades the security of a tenant's data, the integrity of resolution, or the availability of the platform.
If you act in good faith — test only against your own tenant, don't access other customers' data, give us reasonable time to fix before publishing — we will not pursue legal action and will defend you publicly against any third-party claim that arises from your testing.
If you accidentally access another tenant's data while reproducing a bug: stop, delete what you have, tell us. We treat that as a stronger report, not a hostile act.
Confirmation we got the report. Not yet a triage verdict — just "received, looking at it."
Severity (Critical / High / Medium / Low / Info), in-scope confirmation, fix-target ETA. If we disagree it's in scope we'll explain why in detail.
Patched in production. You get a heads-up before the changelog entry goes public so you can prep your write-up.
Default coordinated-disclosure window. We'll work with you on extension if rollout to enterprise customers needs more time, or compression if active exploitation is observed.
We're a small team and a formal bounty program would attract more low-quality submissions than we can triage well. We do issue discretionary thank-you payments (typically $50–$2,000 depending on severity + report quality) and a public credit on the changelog if you want one.
We will revisit a formal program after SOC 2 Type II lands and we have headcount to run it properly.