We test other people's applications for a living, so we take reports about ours seriously and answer them first. No bounty, no NDA, no lawyers — credit and a fast fix.
security@earthshakersecurity.com
Key on request — ask at security@earthshakersecurity.com
earthshakersecurity.com and its subdomains, and any service we operate that carries our name. Our clients' systems are not in scope here — if you have found something in an application we tested, contact its owner, not us.
Non-destructive testing only, against your own accounts, at a rate that will not affect availability. No automated scanning at volume, no social engineering of our people, no physical attempts, and no accessing, modifying or exfiltrating data that is not yours.
We acknowledge within one business day, tell you whether we can reproduce it within three, and agree a fix date with you. You get told when it ships. If we disagree that it is a vulnerability, we explain why rather than closing silently.
Publish whenever you like once it is fixed, or after 90 days if we have not fixed it. We will never ask you to sign anything to report a bug, and we will not threaten anyone acting in good faith under this policy.
We name reporters who want to be named, and we say what was found. If you would rather stay anonymous, that is fine too.
We are a small practice and we do not pay for reports. We are honest about that up front rather than implying a reward and then declining.
Earthshaker SecurityWe find the cracks before they do. Automated and human-verified security testing for web applications.
earthshakersecurity.com · contact@earthshakersecurity.com
Earthshaker Security