Skip to content

Disclosure policy

Embargo Lab practises coordinated vulnerability disclosure. We work privately with the people who maintain the affected software first, and we hold anything sensitive under embargo until a fix is available or an agreed window has passed. This page sets out how that works — in both directions.

Reporting a vulnerability to us

If you believe you have found a security issue in something Embargo Lab publishes or operates, please tell us before telling anyone else. Email security@embargolab.com. If you would like to encrypt your report, ask in a first message and we will arrange a secure channel.

A useful report usually includes:

Please keep testing limited to systems and data you own or are explicitly authorised to assess, and avoid actions that degrade a service, access other people's data, or cause harm.

What you can expect from us

How we disclose our own research

When Embargo Lab reports an issue to a third party, we apply the same discipline we ask of others. We report privately first, give maintainers a reasonable opportunity to remediate, and publish only after a fix ships or a coordinated window closes. We do not sell vulnerabilities, and we do not release working exploits whose only purpose is to make an unfixed issue easier to abuse.

Good-faith safe harbour

If you make a good-faith effort to follow this policy, we will treat your research as authorised, will not pursue or support legal action against you for it, and will work with you if someone else raises concerns. Good faith means respecting the limits above, acting only to the extent necessary to demonstrate a problem, and giving us a reasonable chance to respond before any public disclosure. This safe harbour covers Embargo Lab's own systems and research; it cannot waive the rights of third parties.

Contact

Security reports: security@embargolab.com. General enquiries: contact@embargolab.com. See also our contact page.