Responsible Disclosure

Report a security issue

If you believe you have found a vulnerability in AttackCompass or this website, tell us privately so we can investigate and fix it before public disclosure.

How to report

Send a private report with enough detail to reproduce.

Email security@attackcompass.com. Prefer coordinated reports with reproduction detail and impact. Do not open a public issue with exploit details.

  • A clear description of the issue and its potential impact
  • Affected product surface (web app, marketing site, Agent API, local proxy, or related infrastructure)
  • Steps to reproduce, or a minimal proof of concept
  • Relevant URLs, request/response samples, screenshots, or logs — with secrets redacted
  • Suggested mitigation if you have one

What to expect

We acknowledge, investigate, and coordinate.

Acknowledgement

We aim to acknowledge valid reports within two business days.

Investigation

We investigate impact, reproduce where possible, and prioritize fixes based on severity.

Coordination

We coordinate with you before any public disclosure of the issue you reported.

Credit

With your permission, we can credit reporters who submit valid, in-scope findings.

Scope

What is in scope — and what is not.

Focus reports on AttackCompass systems and practical impact. Out-of-scope testing wastes time on both sides.

In scope

  • AttackCompass web application and authenticated APIs
  • www.attackcompass.com marketing site and related public routes
  • Client-mode / local-proxy paths that handle engagement data
  • Authentication, session, authorization, or entitlement flaws with practical impact
  • Injection, XSS, CSRF, SSRF, or similar web vulnerabilities with demonstrated impact
  • Insecure handling of credentials, tokens, or engagement media with demonstrated impact

Out of scope

  • Social engineering, phishing, or physical attacks against people or offices
  • Denial-of-service, volumetric flooding, or resource-exhaustion testing
  • Automated scanner output without a clear, reproducible impact
  • Issues in third-party services we use (Auth0, Paddle, hosting providers) — report those to the vendor
  • Missing security headers or best-practice nits without a practical exploit path
  • Spam, account support, billing, or product feature requests

Ground rules

Good-faith testing only.

We support researchers who act carefully and keep customer and engagement data out of harm's way.

Do not disclose publicly first

Do not post vulnerability details in public issues, social media, forums, or chat before we have a chance to investigate and fix.

Stay within authorized testing

Only test systems you are allowed to test. Do not access other customers' data, destroy data, or disrupt production availability.

Minimize data access

If you encounter personal data or engagement content, stop, report what you found at a high level, and do not exfiltrate or retain more than needed to demonstrate the issue.

No extortion

We do not pay ransoms or negotiate under threat of disclosure. Good-faith coordinated reporting is welcome.

Other channels

Use the right inbox.

Understand the security model

See what AttackCompass stores, what Client mode protects, and what remains server-readable.

Read the Security Model