We take security seriously โ including our own. If you discover a vulnerability in our systems or products, we want to hear from you. This policy explains how to report responsibly and what to expect from us.
ISec Intel is committed to working with security researchers to identify and remediate vulnerabilities. We will act in good faith toward researchers who comply with this policy โ no legal action will be taken against researchers who follow these guidelines.
We consider responsible disclosure a form of collaboration. Our team respects the skill and effort required for security research, and we aim to respond quickly and with appreciation for your work.
| Asset | In Scope | Notes |
|---|---|---|
| isecintel.com | โ In Scope | Main website and web application |
| *.isecintel.com | โ In Scope | All subdomains |
| API endpoints | โ In Scope | api.isecintel.com and related APIs |
| Mobile applications | โ In Scope | Official ISec Intel apps if published |
| Third-party services | โ Out of Scope | Vendors we use but do not control |
| Social media accounts | โ Out of Scope | LinkedIn, Twitter, etc. |
| Client environments | โ Out of Scope | Never in scope without explicit written auth |
Send your report to security@isecintel.com. Include:
Encrypt sensitive reports using our PGP key available at isecintel.com/pgp.txt
ISec Intel will not pursue legal action against researchers who comply with this policy. We consider responsible disclosure research conducted under this policy as authorised activity. If you comply in good faith, we will defend your interests if a third party initiates legal action against you for research covered by this policy.