This page does not authorise testing
Nothing on this page gives you permission to test, scan or probe any system, whether it belongs to GreyNod Labs, our clients or anyone else. Testing requires prior written authorisation and an agreed scope. Testing without authorisation may be unlawful, and this page does not change that.
What is in scope
Only assets owned by GreyNod Labs, or that the owner has explicitly authorised in writing for testing, are eligible. This website, at greynodlabs.com, is ours. Client websites and third-party platforms are not eligible for testing under this page.
How to report
Email greynodlabs@gmail.com with the subject "Security report". Please include:
- what you found and where (URL, feature or system);
- clear steps to reproduce it;
- the impact you believe it has;
- how we can reach you, and whether you would like to be acknowledged.
If you come across a possible issue by chance, please report it without exploring it further.
Safe reporting and minimal verification
- Verify only as far as needed to show that the issue is real. Use your own accounts and data where possible.
- Do not access, copy, keep or share more data than the minimum needed. Stop and tell us straight away if you encounter personal or sensitive data.
- Stop and tell us if anything you do affects the availability or integrity of a service.
Not permitted
- Denial-of-service or load testing.
- Phishing, social engineering or physical attacks.
- Destructive actions, such as modifying or deleting data.
- Persistence, such as leaving backdoors, and any use of malware.
- Unnecessary access to sensitive data, or using access you gained to reach other systems.
- Testing third-party systems, or any system you are not authorised to test.
Confidentiality and coordinated remediation
We will treat your report as confidential and use it to fix the issue. Please keep the details private until we have had a reasonable opportunity to fix it, and talk to us before disclosing publicly. We may ask you for more information, and may ask you to confirm a fix.
Acknowledgement
If you would like credit, tell us how you would like to be named. Acknowledgement is optional and at our discretion, and we will not name you without your agreement.
What we do not promise
We do not offer a bounty or reward, and we do not promise a particular response or fix time. We cannot promise immunity from legal action or any automatic safe harbour. We will consider each report on its own facts.
Clients and their systems
If you find an issue in a client's website that we built or maintain, report it to us in the same way, without testing further, and we will pass it to the client. Authorised client engagements are covered by our VAPT scope and rules of engagement.
