Disclosure policy
Embargo Lab practises coordinated vulnerability disclosure. We work privately with the people who maintain the affected software first, and we hold anything sensitive under embargo until a fix is available or an agreed window has passed. This page sets out how that works — in both directions.
Reporting a vulnerability to us
If you believe you have found a security issue in something Embargo Lab publishes or operates, please tell us before telling anyone else. Email security@embargolab.com. If you would like to encrypt your report, ask in a first message and we will arrange a secure channel.
A useful report usually includes:
- a clear description of the issue and why you believe it is a security problem;
- the affected component, version, or URL;
- the steps, inputs, or proof-of-concept needed to reproduce it;
- its impact as you understand it, and any suggested remediation.
Please keep testing limited to systems and data you own or are explicitly authorised to assess, and avoid actions that degrade a service, access other people's data, or cause harm.
What you can expect from us
- Acknowledgement. We aim to confirm receipt of a report promptly and to keep you updated as we triage and coordinate a fix.
- Coordination. We work with the relevant maintainers or vendors toward a remediation, and we share credit with everyone involved.
- Embargo. We do not publish technical details before a fix is available or an agreed disclosure window has elapsed — a coordinated window of up to 90 days by default, extended when a fix genuinely needs more time.
- Credit. With your permission, we are glad to acknowledge your contribution publicly once an issue is resolved.
How we disclose our own research
When Embargo Lab reports an issue to a third party, we apply the same discipline we ask of others. We report privately first, give maintainers a reasonable opportunity to remediate, and publish only after a fix ships or a coordinated window closes. We do not sell vulnerabilities, and we do not release working exploits whose only purpose is to make an unfixed issue easier to abuse.
Good-faith safe harbour
If you make a good-faith effort to follow this policy, we will treat your research as authorised, will not pursue or support legal action against you for it, and will work with you if someone else raises concerns. Good faith means respecting the limits above, acting only to the extent necessary to demonstrate a problem, and giving us a reasonable chance to respond before any public disclosure. This safe harbour covers Embargo Lab's own systems and research; it cannot waive the rights of third parties.
Contact
Security reports: security@embargolab.com. General enquiries: contact@embargolab.com. See also our contact page.