Security

If you have found a vulnerability in this site, in something we run, or in something we built for a client, we want to hear about it, and we will treat you as a colleague, not a threat.

How to report

Email the details to the address below. Include what you found, where, how to reproduce it and what you think the impact is. Encrypted mail is welcome; ask for a key.

hello@breakfirst.dev

What we do with it

  • We acknowledge your report within one working day.
  • We tell you what we found when we looked, and what we are doing about it.
  • We fix issues in our own systems first and tell you when the fix is live.
  • If the issue is in a client system, we route it to them and keep you informed as far as they allow.
  • We credit you, by name or handle, if you want that.

What we ask

  • Do not access, change or delete data that is not yours; use test accounts where you can.
  • Do not run denial-of-service or volumetric tests against systems you were not asked to test.
  • Give us a reasonable time to fix before you publish.
  • Stay within the law. If you are not sure, write to us first.

Research that follows these rules is welcome here. We will not pursue or support legal action against anyone who reports in good faith and stays within them.

Machine-readable policy