Skip to content
Security

Responsible Disclosure Policy

We test other people's systems for a living, so we take reports about our own seriously. If you believe you have found a security vulnerability affecting ExploitLab, we want to hear from you.

Where to send reports

Email hello@exploitlab.io with "Security vulnerability report" in the subject line. Please do not open a public issue or post details publicly before we have responded.

ExploitLab does not currently operate a formal bug-bounty programme, and we do not offer monetary rewards for reports. We will credit researchers who ask to be credited.

What to report

  • Vulnerabilities affecting exploitlab.io and systems we clearly operate
  • Authentication or authorization weaknesses
  • Injection, deserialization or remote code execution issues
  • Sensitive data exposure or misconfigured storage
  • Business logic flaws with a demonstrable security consequence

What to include

  • A clear description of the issue and its likely impact
  • The exact URL, endpoint or component affected
  • Minimal, non-destructive reproduction steps
  • Any supporting request/response evidence, with sensitive data redacted
  • How you would like to be credited, if at all

Prohibited activities

  • Denial-of-service, volumetric or stress testing
  • Social engineering of our staff, customers or suppliers
  • Physical intrusion attempts
  • Accessing, modifying, exfiltrating or destroying data that is not yours
  • Automated scanning that degrades service availability
  • Public disclosure before we have had a reasonable opportunity to respond

Our response process

  1. Within 3 business days

    We acknowledge receipt of your report.

  2. Within 10 business days

    We provide an initial assessment and a triage decision.

  3. Ongoing

    We keep you updated on remediation progress at reasonable intervals.

  4. After remediation

    We confirm the fix and agree any coordinated disclosure timing with you.

Safe harbour

If you make a good-faith effort to comply with this policy during your research, we will not pursue or support legal action against you in relation to that research, and we will work with you to understand and resolve the issue quickly.

This commitment applies only to systems ExploitLab operates. It does not authorize testing of our clients' systems, third-party services we use, or any system outside our control. It also cannot waive the rights of third parties or override applicable law.

This safe-harbour wording is a draft position and is subject to review by qualified legal counsel before it is treated as binding.