Report a vulnerability in our systems
Reports go to hello@principlebreach.com. The machine-readable version of this policy is at /.well-known/security.txt.
In scope
In scope
principlebreach.com and its subdomains
In scope
Our API and admin interface
In scope
Our public repositories
Not in scope
Client systems
Third-party services we use
Findings with no security impact
Denial of service
Social engineering
Scanner output with no exploit
How to report
Email is the only channel. There is no form and no portal. One issue per email.
We do not run a bug bounty and offer no payment for reports. You get a reply, a severity assessment, and public credit if you want it.
Send to
hello@principlebreach.comEncrypt anything that contains a working exploit, credentials, or data you reached. The key below is fetchable from /pgp-key.txt.
Include in your report
- The URL, endpoint, or repository, and the exact request that triggers the issue.
- Numbered steps to reproduce, from an unauthenticated state or an account you created yourself.
- The impact: what an attacker could reach, stated separately from what you actually did.
- Any accounts, test data, or artefacts you created, so they can be cleaned up.
PGP key C3DC 3424 CBE3 0B94 59AF FBB8 9B06 8774 AE24 3BB4
What happens next
01
Report
Email the report, encrypted to the key below if it contains anything sensitive. One issue per email.
You
02
Acknowledge
You get a reply confirming receipt and whether the issue is in scope.
Within 7 working days
03
Reproduce and assess
We reproduce the issue and assign a severity. If we cannot reproduce it, we tell you what we tried.
Us
04
Fix and disclose
We tell you when a fix ships and agree a disclosure date. Absent any other agreement, the default is 90 days from your first report.
Both
Rules of engagement
Staying inside these rules is what the safe harbour below is conditioned on.
- Test only against in-scope assets, and only with accounts you created yourself.
- Stop at proof. Show that access is possible and go no further. Do not read, copy, alter, or keep anyone else's data.
- Do not degrade the service. No denial of service, no destructive payloads, no traffic heavy enough to affect availability.
- Do not pivot. Access to one in-scope system is not authorisation to reach anything behind it.
- Delete anything you kept, and any accounts or content you created, once the report is closed.
- Keep the finding private until the agreed disclosure date.
Safe harbour
Good-faith research inside the scope and rules above is authorised as far as this company is concerned.
- We will not pursue legal action or refer you to law enforcement for good-faith research within this policy.
- Accidentally stepping out of scope does not void this, provided you stop as soon as you notice, tell us, and do not use or keep what you reached.
- We can only authorise testing against our own systems. Nothing here covers a client's, a provider's, or any third party's assets.
- This policy does not override criminal law in your jurisdiction or in India, where the company is registered.