Coordinated disclosure policy
Version 1.0 · in effect since 23 August 2026
This document describes how we investigate, report, and publish security findings. It is public and binding: it constrains us before anyone else.
Scope
We analyze public surface only: what any browser receives when visiting a site, with no credentials, no parameter tampering, and no exploitation tooling.
We do not test credentials, do not manipulate identifiers to reach someone else’s data, do not run scanners or brute force, do not download databases, and do not engage in social engineering.
If a finding would require crossing that line, we do not investigate it. We report what was observed and recommend an authorized audit.
The clock
Within 7 days of verifying a finding, we send the full technical write-up to the owner. From that moment, 90 calendar days start running.
All we expect in the first week is an acknowledgement: confirmation that the email arrived. Not a fix, not a plan. If there is no reply within 7 days, we retry through another channel.
Fix it earlier and we publish afterwards with the case closed. Ask for an extension with a plan and a date and it is granted. No response, and after 90 days the case becomes publishable.
The 90 days are not shortened, and that is not deference to the vendor: while the vulnerability is still live, publishing sooner does not punish them — it hands anyone the map with people’s data still exposed. We press on the acknowledgement, which reveals nothing; never on the exposure.
When a finding actively exposes personal data, we also notify the relevant authority. In Argentina, that is the AAIP, under Law 25.326. That notification does not depend on the vendor replying.
Anonymity
We do not name. Ever. Not while the vulnerability is live, not once remediated, not after the deadline passes. Anonymizing is not a temporary concession: it is the format.
We publish the vulnerability class, the mechanism, the impact, and how to prevent it. We do not publish names, domains, paths, versions, payloads, screenshots, or exact dates.
No case is published while the vulnerability is live. Once it is fixed, even if someone recognizes the case, there is nothing left to exploit.
What we do not do
We do not charge for silence. We ask for no bounty, no contract, and nothing in return for not publishing. A report never arrives with a sales pitch attached.
We do not publish exploits, proofs of concept, or reproducible steps.
We do not comment on the business. We pass no judgment on an organization’s soundness or professionalism. A finding describes a configuration at a point in time; it is not a verdict on whoever built it.
If your organization received a report
There is no threat here. We wrote to you because we found something from the outside and would rather you hear it from us.
All we need is an acknowledgment. You can ask for an extension with a plan and a date, request technical clarification, or ask us not to publish if you can show the finding is wrong. If you are right, the case is dropped.
We will not name you publicly, we will not publish anything exploitable, and we will not use this to sell you anything.
Mistakes
If we publish something wrong, we correct it with a dated note. We do not edit silently.
If a published case turns out to be identifiable, we unpublish first and discuss afterwards.
Contact
To report something to us, the same channel. The same policy applies to us.