Vulnerability disclosure
Reporting a vulnerability to us
Two channels, and picking the right one matters. The bounty publishes what you send it within seconds. This policy does the opposite: we hold your report until the defect is fixed. Use this one for anything you do not want published the moment you send it.
Version 0.2 · 28 September 2026 · security.txt
How to reach us
A person reads these. There is no form and no ticket queue.
info@endstop.systems · put Vulnerability report in the subject | |
| Telephone | +1 650-645-0171, if you would rather speak to someone |
| Post | Alnair LLC, 310 Comal Street, Suite 262, Austin, TX 78702, USA |
Report in English. You do not have to identify yourself, and an anonymous report is still acted on; we simply cannot pay one or tell you what happened next.
Which channel, and why the difference matters
Use this policy
For anything where publication before a fix would put someone at risk: a defect in the broker, the edge, this site, the published crates, or in a build a design partner is running. Also for anything you would rather keep private for any reason of your own.
Your report stays between us until it is remedied.
Use the bounty
For the four disclosed targets on the bounty page: the interpreter's bounds check, the signing key, the host, and halting the emulated device. That is a live range with money on it and a deliberately public log.
Every program you submit there is published with its verdict within seconds.
The two are not the same instrument and we would rather say so than let the bounty be mistaken for a disclosure policy. A range exists to prove a claim in public. A disclosure policy exists to get a defect fixed before it hurts anyone. If you are in doubt, use this policy. We can always agree to publish afterwards; we cannot unpublish.
The range is a temporary stage; §6 explains when it ends.
What we commit to
- Acknowledge within 3 working days
A human reply confirming we have it. If you do not hear back in that time, assume the mail went astray and try the telephone.
- An assessment within 10 working days
Whether we agree it is a defect, how severe we think it is, and what we intend to do. If we disagree, we will explain why.
- A fix, or a reason there is not one
We will keep you informed while it is open, at a cadence agreed with you.
- Public disclosure within 90 days, by default
We publish what was found and what changed, and we would rather do it jointly with you. If a fix will take longer than 90 days we will tell you why and agree a date, not let the clock run out quietly. You are free to disclose on your own timetable, and we ask only that you give us the 90 days first.
- Credit, if you want it
Named however you like, or not at all. We will ask before we name you.
These are commitments about our conduct, not a warranty. Where a defect sits in something a design partner is running, their own notification arrangements come first and we will say so at the assessment step.
Safe harbour
Research conducted in good faith under this policy is authorised. Specifically, and for the systems in §5:
- We will not initiate or support legal action against you for it, including under computer-misuse law.
- We authorise the circumvention of technical measures we use to protect those systems, to the extent needed for the research, and we will not bring a claim under anti-circumvention law for it. Circumventing our protections is the job; a policy that quietly leaves that actionable is not a safe harbour.
- We exempt good-faith research under this policy from any restriction in our terms of use or acceptable-use terms that would otherwise prohibit it. Where the two conflict, this policy governs for research inside §5.
- If a third party brings an action against you for work that complied with this policy, we will make it publicly known that your actions were authorised.
Good faith here means: stay within the systems named in §5; take only the minimum data needed to show the defect exists, and tell us if you take any; do not degrade a service others are using; do not access, alter or destroy anyone else's data; and report to us promptly.
If a report necessarily contains someone else's personal data, send the minimum, say so in the report, and do not retain a copy after we confirm receipt. We would rather have a report that is thin on that detail than one that puts a third party at risk to prove a point.
This harbour reaches only claims that are ours to bring or waive. It does not bind anyone else — not our cloud providers, not a design partner whose machine an Endstop build is sitting in, and not any authority. Where our systems run on infrastructure we rent, that provider's own terms still apply to you and we cannot waive them on their behalf. If you are unsure whether something is ours to authorise, ask before testing.
Some acts are offences whatever we say about them, and no policy of ours can authorise them. Destroying data, extorting us, attacking a third party's systems from ours, or going after people rather than machines sits outside this harbour, and we will not protect it.
Step outside §5 and the authorisation ends there, not retroactively for the work that was inside it.
Scope
In scope: endstop.systems and alnair.dev; the target endpoint at redteam.endstop.systems and the Alnair-controlled systems behind it; and the published interpreter crate. An Endstop build in a design partner's environment is in scope only when that partner has named the asset and authorised the test in writing.
Out of scope: denial of service against infrastructure other than the emulated device itself; social engineering of our people or our suppliers; physical attacks; anything aimed at a person rather than a machine; and other tenants or hosts on the cloud platforms we rent from. Findings in third-party services should go to that third party, and we are happy to help you route them.
Reports about the four disclosed bounty targets belong on the bounty, where they are paid. Reports under this policy are not paid by default, though we may pay for something serious and will say so when we do.
Why this page exists separately
The Cyber Resilience Act requires a manufacturer to operate a coordinated vulnerability disclosure policy and to name a single, easily found point of contact that a reporter can reach by the means they prefer, including without an automated tool. Those obligations bite before we place anything on the market, and a policy written the week before a deadline is a worse policy.
This policy is versioned and dated at the top. We may change it, and the version in force when you did the research is the one that governs it. Changes are announced here, and a change never withdraws protection from work already done under an earlier version.
Version 0.2, 28 September 2026: the scope names the published interpreter crate only, since the signer crate is not yet published; the bounty target is named as the emulated device; and the bounty's publication is described as programs and verdicts rather than everything submitted. No protection was narrowed.
There is also a tension worth naming, because a reader will find it anyway. Coordinated disclosure means holding detail until a defect is remedied. The bounty publishes every attempt within seconds. Both are deliberate, and the reason they can coexist is timing.
We run the range in the open now, before anything of ours is in the field, because the thing being tested at this stage is the foundation, not a deployment. Nobody is exposed by publishing an attempt against a target that exists to be attacked, and a claim about a boundary is worth what its public attack record is worth. The log is intended to be durable, but operational completeness is not a cryptographic guarantee: outages, failed ingestion and lawful removals must be disclosed rather than silently hidden.
That changes when the product does. Once Endstop is running in a customer's cell, an attack log that publishes live would be publishing against somebody else's machine, and the range converts to a conventional coordinated-disclosure programme on the terms above. We would rather state that now, while it costs us nothing to promise, than be argued into it later by the first client with something to lose.