Responsible vulnerability research for a safer open-source ecosystem.
We study the software the world depends on, report what we find privately to the people who maintain it, and keep anything sensitive under embargo until there is a fix.
Our approach
A small set of principles we don't bend.
Embargo Lab exists to make widely-used software safer without putting its users at risk along the way. How we work follows from that.
Depth over noise
We read code closely and confirm a finding before we ever raise it. No automated dumps, no speculative reports — only issues we understand and can substantiate.
Coordinated disclosure
We report privately to the people who maintain the software first, and work with them toward a fix. Maintainers are partners, not adversaries.
Embargo discipline
Nothing sensitive is published before a fix is available or an agreed disclosure window has passed. The name on the door is a promise about timing.
Credit where due
We acknowledge the maintainers who fix issues and the researchers who find them, and we welcome the same courtesy in return.
Found a vulnerability? We'll handle it responsibly.
We follow coordinated disclosure in both directions: we report what we find under embargo, and we welcome good-faith reports under the same terms. Our policy explains how to reach us, what to include, and what you can expect back.
Get in touch.
For security reports, coordination, or general enquiries — we read everything.