How to report
Email [email protected], in English or Spanish. Please include:
- What is affected: the address, page or component.
- The steps to reproduce it, as short as you can make them.
- The impact you believe it has.
- A proof of concept that does not harm anyone, and how to reach you.
The same contact is published in machine-readable form in our security.txt file.
What is in scope
The Corvidint website at corvidint.com and what it serves: the pages, the analytics endpoints and the briefing form.
Out of scope: denial of service and volumetric attacks, social engineering of people, physical attacks, third-party services such as our DNS, network or email providers, automated scanner output without a real impact, and missing best-practice headers with no demonstrated effect.
Rules for safe research
- Test only with your own data and accounts.
- Do not access, change or copy data beyond what you need to show the issue.
- If you reach personal data, stop and tell us.
- Do not disrupt the service.
- Give us reasonable time to fix the issue before you tell anyone else.
Safe harbor
If you act in good faith and follow these rules, we will consider your research authorized, we will not take legal action against you, and if someone else brings a claim over it we will say that it was authorized.
What to expect from us
- We aim to acknowledge your report within five working days.
- We investigate, keep you informed and tell you when it is fixed.
- With your permission, we credit you.
- We do not run a paid bounty at this time.
How the website protects you
Every connection uses TLS with strict transport security. The pages run under a strict content security policy with no third-party scripts, and there are no cookies. The website and its analytics run on our own server.
For how the product itself is secured, read the security overview.