Help Us Keep Our Products
& Subdomains Secure
We deeply value the security research community. If you have discovered a vulnerability across any of our web applications, APIs, or subdomains, please notify us under clear Safe Harbor protections.
Our Legal Safe Harbor Commitment
We will not pursue legal action against researchers who adhere to good-faith disclosure principles.
Good Faith Research
If you conduct security research in compliance with this policy, we consider your research authorized and will work with you to understand and resolve the issue promptly.
No Civil or Criminal Liability
We waive any potential Computer Fraud and Abuse Act (CFAA) or breach of service terms claims against security researchers who access systems unintentionally while testing within scope.
Coordinated Public Credit
Unless requested otherwise, we credit security researchers on our official Hall of Fame once a fix is validated and deployed to production.
Program Scope & Eligibility
Review eligible subdomains, systems, and testing boundaries before conducting research.
| Target Asset / Pattern | Type | Severity Tier | Status |
|---|---|---|---|
*.example.comAll primary subdomains | Web Apps & APIs | Critical - Low | Fully Eligible |
api.example.comCore REST / GraphQL API | Backend API | Critical | Fully Eligible |
auth.example.comSSO & Auth Gateway | Authentication | Critical | Fully Eligible |
app.example.comSaaS Customer Portal | Web Application | Critical | Fully Eligible |
Security Researcher Hall of Fame
Honoring the security experts who helped protect our infrastructure, products, and users.
Samira Rahman
David Chen
Kavita Patel
Alex Rivera
Interactive Security Report Builder
Fill out the report details below to automatically format a structured report and draft an email to security@example.com.
# [SECURITY REPORT] Vulnerability Report Summary **Target Asset:** https://api.example.com/endpoint **Category:** Vulnerability Finding **Severity:** P3 - Medium **Reporter:** Security Researcher (researcher@example.com) **Hall of Fame Credit:** Yes (Handle: Anonymous) **Date:** 2026-07-30 --- ### 1. Vulnerability Description & Steps to Reproduce 1. Step one to reproduce...\n2. Step two... ### 2. Impact & Suggested Remediation Impact details and suggested fixes. --- *Submitted via Responsible Disclosure Portal.*