Skip to content

Security

Responsible Disclosure

We do offensive security for a living. If you find something on endescope.com, you get a fast response, credit, and a Hall of Thanks mention where appropriate.

Scope

All assets under *.endescope.com are in scope. Third-party services (hosting infrastructure, email providers, etc.) are out of scope; please report those directly to the vendor.

Exclusions

  • Automated scans without manual validation
  • SPF/DMARC/DKIM configuration notes (handled separately)
  • Missing security headers without a concrete exploit
  • Rate-limit complaints on public static assets
  • Self-XSS, clickjacking without demonstrated impact
  • Denial of service

Reporting

Email security@endescope.com with vulnerability details, reproducible steps, and optionally a PoC. A PGP key for encrypted communication will launch with the phase-two version of this site.

Our commitment

  • Response within 24 hours on business days
  • Status update every 72 hours until resolution
  • Safe harbor: we do not pursue security research conducted in good faith
  • Hall of Thanks credit (if desired)

No bounties yet, but

We currently do not pay monetary bounties on endescope.com itself. For critical findings we send a token of thanks (swag, reference letter, networking) and offer prominent Hall of Thanks placement.

Last updated: 2026-04-22

Newsletter

Substance over noise

One email every two weeks with a new blog post or a technical deep dive. No clickbait.