Security

Responsible disclosure

If you have found a security issue in planckdefense.com or in infrastructure we operate, we want to hear about it. Send good-faith reports to [email protected]. Encrypted mail is welcome, and a PGP key is available on request from the same address.

Reporting

Reporting a vulnerability

Email [email protected]. That address is read by the engineers who run our systems, not a ticket queue, and every report is reviewed by a human. You do not need an account, a form, or a platform profile to reach us.

If you prefer to encrypt, send a plain first message asking for our current PGP key. We will reply with the key and its fingerprint before you share any technical detail, so you can verify what you are encrypting to.

We acknowledge every report within two business days. If the issue is confirmed, we keep you informed through triage and remediation until it is closed.

What a useful report includes

  • The affected asset. The hostname, URL, endpoint, or IP address where you observed the issue, so we can locate it without guesswork.
  • Reproduction steps. The exact requests, inputs, or configuration needed to trigger the behavior. Raw requests and responses help us more than screenshots.
  • Impact. What an attacker could realistically do with the issue: read data, escalate privileges, pivot into other systems, or disrupt a service.
  • Your contact details. An email address for follow-up questions, and the name or handle you would like credited if the finding is confirmed.
Scope

What this policy covers

This policy applies to systems that Planck owns and operates. If you are unsure whether an asset belongs to us, ask before you test. A short email costs nothing and keeps you inside the policy.

In scope

Testing under this policy is limited to assets under our direct operational control.

  • planckdefense.com and the subdomains we operate under it, including this website and its supporting services.
  • Planck-operated production infrastructure that serves our corporate systems, such as our mail and DNS configuration for planckdefense.com.
  • Public-facing services we run ourselves, where the vulnerability lies in our code, our configuration, or our exposure.

Out of scope

The following are excluded. Testing them is not authorized by this policy under any circumstances.

  • Client systems, client environments, and any data connected to a client engagement
  • Third-party services and platforms we use but do not operate
  • Social engineering of Planck staff, including phishing and pretexting
  • Physical attacks against people, premises, or hardware
  • Denial of service testing or any activity intended to degrade availability
  • Automated scanner output without a demonstrated security impact
Safe Harbor

Safe harbor for good-faith research

We will not pursue or support legal action against researchers who discover and report vulnerabilities in our systems in good faith and within the terms of this policy. Research conducted under these terms is authorized activity as far as we are concerned, and we will not refer it to law enforcement. We spend our working lives on the other side of this exchange, reporting vulnerabilities to vendors, and we hold ourselves to the standard we expect from them.

Good faith has a concrete meaning here. It means you access only what is necessary to demonstrate that an issue exists, and nothing more. Specifically, you agree to the following conditions.

On disclosure timing, we ask for coordination rather than silence. Tell us what you found, give us a realistic window to fix it, and we will work with you on when and how details become public. If you are ever unsure whether something you plan to do falls within this policy, write to [email protected] first and ask. We answer those questions quickly, and asking never counts against you.

Our Commitment

What happens after you press send

A disclosure policy is only as good as the response behind it. This is the sequence every report moves through, handled by engineers rather than a support layer.

Acknowledge

You receive a human acknowledgment within two business days, confirming the report arrived and naming the person handling it.

Triage and validate

An engineer reproduces the issue, assesses its severity and reach, and comes back to you with questions if anything is unclear.

Remediate

Confirmed issues are fixed with a priority that matches their severity. We tell you when the fix ships so you can verify it yourself.

Credit

If you want recognition, we credit you by name or handle once the issue is resolved. If you prefer anonymity, we respect that without question.

We do not currently run a paid bug bounty program, and we say so plainly so that expectation is set before your report arrives, not after. What we offer instead is a serious response: engineers reading your report, honest communication about severity and timelines, public credit if you want it, and a direct line to the people fixing the issue.

Get Started

We would rather hear it from you

Good reports make our systems better, and we treat the researchers who send them as colleagues. For questions about this policy, or about how we handle data more broadly, get in touch.