Endstop

Rev 0.3.4 · in integration

Privacy notice

What we collect, and what we publish on purpose

This notice covers site delivery, optional Google Ads measurement, private inquiries and the bounty's public attack log. Programs submitted to the bounty are published with their verdicts within seconds; inquiry form answers are not sent to Google Ads.

Updated 28 September 2026 · Alnair LLC, controller

Ads

Optional advertising measurement

Investor request forms send your name, email, firm or individual status, role, investment focus and optional message to our team through Resend so we can respond. Submitting a request does not require advertising measurement consent or subscribe you to a mailing list.

With your permission, we load the Google Ads tag to measure visits and completed fit-assessment and investor inquiries attributable to our ads. We also measure engaged evidence reading: at least 60 seconds on visible, focused evidence, architecture or source pages plus a click to architecture, source or an evidence artifact. A temporary per-tab session record avoids counting this more than once per session and expires after 30 minutes of inactivity. Google receives browser and device information, IP address, page information, advertising click identifiers where available, cookies and conversion events. We send a random submission identifier to avoid counting the same event twice. We do not send names, email addresses or form answers to Google Ads, and enhanced conversions and personalized advertising are disabled.

Choose Allow measurement or Decline in the notice. Google measurement stays off until you allow it. You can change your choice using Privacy choices in the footer. Withdrawing permission stops future measurement; it does not erase data already sent to Google.

We remember your choice on this device for up to 180 days. Google advertising cookies follow Google's expiration settings. Google processes measurement data under its privacy policy; see also how Google uses information from sites. Data may be processed outside your country. Optional measurement is based on your consent.

§1

Who we are

Alnair LLC, 310 Comal Street, Suite 262, Austin, TX 78702, USA, is the controller for the processing described here. Endstop is our product and endstop.systems is our site.

Write to info@endstop.systems about anything on this page. It reaches the people doing the work rather than a queue.

If you are in the UK or the EU, you may also complain to your own national data protection authority. You do not have to come to us first.

§2

The bounty publishes what you submit

This is the part that matters, so it comes first rather than last.

When you submit a program to the target endpoint, the following appears on the public attack log within seconds, and stays there:

  • Your program, in full, as you wrote it.
  • The verdict the target returned.
  • A researcher tag. This is an HMAC of your IP address and TLS shape under a secret we hold, cut to six characters. It groups your submissions together so a reader can follow one line of attack. The tag does not disclose the address by itself, but it is pseudonymous rather than anonymous data and may still be personal data. The secret prevents a log reader from directly recomputing it; the tag is kept short so that even if the secret leaked, one tag would answer to a few hundred addresses rather than to yours alone.
  • An optional name, if you supply one. It is self-declared and we do not verify it, because the programme is deliberately pseudonymous and a verified identity is not a thing we want to be holding.
  • An optional note, if you supply one, describing the attack you are trying.

The name and note fields are screened before they appear, and we may withhold either when it is used for something other than attacking the box. When we withhold, the row says so; the attempt, its program, its verdict and its timestamp always stay. That policy and its limits are on the bounty page.

Send nothing you want kept private

The programme exists so that a claim about a boundary can be checked by strangers, and a log that could be edited afterwards would not do that job. Treat everything you put through the endpoint as permanent and public. If you have something to report that you do not want published on those terms, do not submit it to the endpoint. Report it under the vulnerability disclosure policy instead, which is a different process with different promises.

§3

Everything we process, and why

Processing activities, data and legal basis
WhenWhatWhy, and on what basis
You read this site Cloudflare serves the pages and records request metadata, including IP address, for delivery and abuse prevention. Cloudflare Insights collects aggregate page analytics. Our legitimate interest in serving a site that stays up and is not abused. Art. 6(1)(f)
You submit to the endpoint Your program, the verdict, an HMAC-derived tag, and any name or note you supply. Your raw IP address is used to compute the tag and to rate-limit; the log stores the tag, not the address. Our legitimate interest in keeping a complete, permanent, public record of every attempt against a safety claim we make. A record that could be edited would not be evidence. Art. 6(1)(f)
You claim a reward Whatever is needed to pay you and to satisfy tax and sanctions obligations: a name, a payment route, and tax information. Performing the agreement to pay you Art. 6(1)(b), and complying with legal obligations that bind us as a US company Art. 6(1)(c)
You email us Your address, your message, and anything you attach. Answering you, and our legitimate interest in keeping a record of what was discussed. Art. 6(1)(f)
You submit a pilot intake Your name, work email, company or team, and the technical information you enter about the machine and requested boundary. Assessing the request, responding to you and taking steps toward a possible engagement. Art. 6(1)(b)
You allow advertising measurement Browser and device information, IP address, page information, advertising click identifiers where available, cookies and conversion events, sent to Google Ads only after you choose Allow measurement. Names, email addresses and form answers are not sent. Measuring visits and inquiries attributable to our ads. Your consent, which you can withdraw under Privacy choices Art. 6(1)(a)
You submit an investor request Your name, email, firm or individual status, role, investment focus and optional message. Responding to your request and taking steps toward a possible investment discussion. Art. 6(1)(b)
You report a vulnerability Your report and your contact details, held privately until the finding is remedied. Our legitimate interest in the security of our own systems and our customers' Art. 6(1)(f)

There is no account to create, no advertising shown on this site and no automated decision-making with legal effect. Advertising measurement is optional and stays off until you allow it. We do not sell personal information or disclose it to third parties for their own advertising. The persistent researcher tag intentionally groups activity at this endpoint; it is not used to follow a person across unrelated sites.

We do not ask for and do not want special category data: nothing about health, beliefs, politics, biometrics or anyone's sex life belongs in a program, a note or a vulnerability report. If you send it we will remove it.

Nothing here is aimed at children. The site is a technical document and the bounty pays only people who have reached the age of majority where they live.

We hold what we have with measures appropriate to the risk: secrets kept out of source control, the researcher tag computed under a key we do not publish, transport encrypted, and access limited to the people doing the work. That is a statement about care, not a guarantee against every attacker, and we would rather say it that way.

§4

Where it goes, and for how long

The site and the edge in front of the endpoint run on Cloudflare. Pilot-intake and investor-request email is delivered through Resend. Google receives advertising measurement only if you allow it. The emulated target and the broker run on a Google Cloud virtual machine in the United States. Email is hosted for us. These providers and their documented subprocessors process data on our behalf; payment, tax or legal providers may also receive the minimum information needed when a reward is claimed.

Alnair is established in the United States. Data may therefore be processed in the United States and in other locations used by those providers, including when you are in the EU or UK.

Retention
Attack log entriesIndefinitely, by design. The log is the evidence and it is meant to outlive us.
Request and server logsShort operational retention, then discarded.
Reward payment recordsAs long as tax and financial law requires us to keep them.
CorrespondenceAs long as the matter is live, and then as long as we may need it to answer for what we said.
Pilot intakeAs long as the assessment or resulting engagement is live, then retained with the related correspondence or deleted on request where the law permits.
Investor requestsAs long as the discussion is live, then retained with the related correspondence or deleted on request where the law permits.
§5

Your rights, and the one we will argue about

If data protection law applies to you, you can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, object to processing we do on the basis of legitimate interests, and complain to your supervisory authority. Ask at info@endstop.systems and we will answer.

The attack log needs a separate assessment. We rely on the integrity of a public evidence record as a legitimate interest, but that does not automatically defeat a valid objection or deletion request. We will assess each request under the law that applies, document the balancing decision and remove optional names or notes where retention is not necessary. The technical program and verdict may remain where the legal basis permits it.

The way to avoid this entirely is in §2: report it privately under the disclosure policy rather than submitting it to the endpoint.

§6

Changes

This notice is versioned and dated at the top. When it changes materially we will say what changed rather than silently reissuing it.

28 September 2026: the processing table now lists optional advertising measurement and investor requests, the recipients paragraph names Resend for both inquiry forms, and a retention row covers investor requests.