Disclosure
The vendor hears first
Then, ninety days later, everybody else, fixed or not. The terms are written down in advance and are the same for every vendor, because a timeline decided case by case is one that can be leaned on.
The clock
What happens, and when
From the day we have something worth reporting. A slow inbox does not buy extra time.
-
We report it
Privately, to the vendor, with everything we have.
The reproduction, the analysis, the affected versions and the proof of concept, sent to a published security contact or the most plausible address. No public mention, no teaser, no conference abstract with the details removed.
-
You acknowledge
We ask for an acknowledgement within seven days.
Not a fix, just confirmation that a human has it. If nothing comes back we try another channel, then a national CERT or the relevant coordinating body. The clock below does not stop while we look for somebody to talk to.
-
You fix it
The window is ninety days, from the day we reported it.
It starts at the report, not at your acknowledgement. If a fix is genuinely in progress we extend by fourteen days on request, and further by agreement where there is a release date to point at. We will not extend indefinitely: an open-ended window is the same as no window.
-
We publish
On the date, whether or not it is fixed.
An advisory with the analysis and the full timeline, including every date the vendor was contacted and what came back. If it is fixed, it says so and credits the people who fixed it. If not, it says that too, and describes what users can do meanwhile.
One exception
When it is already being exploited
If a flaw is being used against real people while we sit on it, the window closes to seven days and we publish what users need to defend themselves, fixed or not. Coordinated disclosure exists to get things fixed, not to keep victims uninformed while a release is scheduled.
Commitments
What we will and will not do with a flaw
The timing above is what people ask about. This is what decides which kind of company this is.
-
The vendor hears first
Always, and before anybody else, including a client who commissioned the work when the flaw is in software they use rather than own. Nobody gets a private head start on a vulnerability in somebody else's product.
-
We do not sell to brokers
No exploit broker, no offensive-capability buyer, no government or private buyer of undisclosed flaws, at any price. There is no version of this where a flaw we found stays unfixed because somebody paid for it to.
-
Proof of concept, not weapons
What we publish shows a flaw is real and what it grants. It is not a reliable, drop-in exploit, and where the gap between the two is small we publish less rather than more.
-
Authorised research only
Software we may lawfully research, or a target a client has authorised in writing. We do not touch systems we have no permission to touch, and a client cannot authorise us against something that is not theirs.
-
Other people's data stays other people's
Research runs against software, not somebody's production database. If we encounter real user data we stop, say so in the report, and keep none of it. Proving a flaw never requires real records, and treating it as if it does is how researchers become the incident.
-
Credit where it is due
Vendors who fix things quickly are named for it if they want to be, and the engineer who shipped the fix is credited over the company where we know who they are. Good security response should be worth something publicly.
There is no version of this where something we found stays unfixed because somebody paid for it to.
In reverse
Reporting something to us
Found a flaw in this site, in anything Skull Solutions runs, or in a tool we publish? The same terms apply in reverse. Expect an acknowledgement within seven days, and we will not threaten you, invoice you, or ask you to sign anything before we will listen. You get credited unless you would rather not.
Found something in ours?
Acknowledgement within seven days, and you get credited unless you would rather not.