Security
If you believe you have found a security issue affecting Company Confidential, please report it privately and in good faith.
Contact
Email security@companyconfidential.net. Include enough detail for us to reproduce and assess the issue, but avoid sending unnecessary personal or sensitive data.
Scope
This policy covers companyconfidential.net, its subdomains, and security issues involving our public email/DNS configuration.
Please avoid
- Denial-of-service or resource-exhaustion testing.
- Brute-force attacks, credential stuffing, or password spraying.
- Social engineering, phishing, or contacting third parties.
- Accessing, changing, deleting, or retaining data that is not yours.
- Any testing that materially disrupts the service.
What to expect
We aim to acknowledge credible reports within three business days and provide reasonable updates while a report is being assessed. We do not currently operate a paid bug-bounty programme.
Good-faith research
We will not pursue legal action against researchers who comply with this policy, act in good faith, avoid privacy violations and disruption, and give us a reasonable opportunity to investigate and remediate a reported issue.
Machine-readable policy
The canonical security contact is also published at /.well-known/security.txt.
Company Confidential