Report a vulnerability.
Send it to [email protected]. We acknowledge within 3 business days and we will not pursue you for good-faith research that follows this policy.
How to report
Email upgrade@algodyne.com with enough detail to reproduce the finding: the affected URL, the steps, and what an attacker gains. We acknowledge within 3 business days and will keep you informed until the report is closed. You are welcome to report anonymously.
Safe harbour
We will not bring or support legal action against you for research conducted in good faith under this policy: accessing only what is necessary to demonstrate the issue, stopping as soon as you have proof, not degrading service for anyone else, and not accessing, altering, or retaining data that is not yours. Tell us before you disclose publicly and we will agree a timeline with you.
In scope
- algodyne.com and its subdomains
Out of scope
- Findings that require physical access to a device we do not control
- Volumetric denial-of-service testing
- Social engineering of staff, contractors, or suppliers
- Reports generated by an automated scanner with no demonstrated impact
No bounty
We do not run a paid bounty programme and will not imply one. We will credit you by name in the fix if you want the credit, and we will say so plainly if we decide not to act on a report.