Vulnerability disclosure policy
Last updated: October 7, 2026
In short: if you find a security issue in shadowperimeter.com, tell us. If you act in good faith and follow the rules below, we will not pursue legal action against you.
Scope
- In scope: shadowperimeter.com and its subpages.
- Out of scope: third-party services we use (Formspree, Stripe, Google, Cloudflare, hosting provider), social engineering, physical attacks, and anything not owned by Shadow Perimeter.
Rules
- Test only with your own accounts and data. Do not access, change or keep other people's data.
- No denial-of-service, spam, automated mass scanning or anything that degrades the service for others.
- Stop and tell us as soon as you reach sensitive data or confirm an issue; do not go further to show impact.
- Give us a reasonable time to fix the issue before sharing it publicly (we ask for up to 90 days).
Safe harbor
If you make a good-faith effort to follow this policy, we consider your research authorized, we will not initiate legal action against you for it, and we will work with you to understand and fix the issue. This applies only to our own site; it cannot authorize testing of anyone else's systems.
How to report
Email ceo@shadowperimeter.com with: what you found, where, how to reproduce it, and the impact. Encrypted email is not required. We aim to acknowledge your report within 5 business days. We do not run a paid bounty program, but we are glad to credit you if you wish. See also our security.txt.