Acknowledgement
We aim to acknowledge valid reports within two business days.
Responsible Disclosure
If you believe you have found a vulnerability in AttackCompass or this website, tell us privately so we can investigate and fix it before public disclosure.
How to report
Email security@attackcompass.com. Prefer coordinated reports with reproduction detail and impact. Do not open a public issue with exploit details.
What to expect
We aim to acknowledge valid reports within two business days.
We investigate impact, reproduce where possible, and prioritize fixes based on severity.
We coordinate with you before any public disclosure of the issue you reported.
With your permission, we can credit reporters who submit valid, in-scope findings.
Scope
Focus reports on AttackCompass systems and practical impact. Out-of-scope testing wastes time on both sides.
Ground rules
We support researchers who act carefully and keep customer and engagement data out of harm's way.
Do not post vulnerability details in public issues, social media, forums, or chat before we have a chance to investigate and fix.
Only test systems you are allowed to test. Do not access other customers' data, destroy data, or disrupt production availability.
If you encounter personal data or engagement content, stop, report what you found at a high level, and do not exfiltrate or retain more than needed to demonstrate the issue.
We do not pay ransoms or negotiate under threat of disclosure. Good-faith coordinated reporting is welcome.
Other channels
See what AttackCompass stores, what Client mode protects, and what remains server-readable.
Read the Security Model