grid lines

[ Vulnerability Reporting & Safe Harbor ]

Responsible Disclosure Policy

Guidelines for security researchers to responsibly test and report security vulnerabilities in AlienGate infrastructure.

Effective Date: September 2026

1. Our Commitment to Security

At AlienGate, the security of our platform and customer data is paramount. We value the contributions of the independent security research community and encourage responsible reporting of potential vulnerabilities.

2. Safe Harbor Agreement

If you conduct security research and report vulnerabilities in compliance with this policy:

  • We will not pursue legal action against you.
  • We will work with you to understand and validate your findings.
  • We will recognize your contribution if you are the first to report a confirmed issue.

3. Rules of Engagement

To qualify for Safe Harbor, researchers must strictly adhere to the following rules:

  • Do not access or modify customer data. Test only using your own accounts or authorized test environments.
  • Avoid service disruption. Do not perform Denial of Service (DoS/DDoS), spamming, or brute-force attacks against AlienGate systems.
  • Maintain confidentiality. Do not disclose vulnerability details publicly until AlienGate has validated and resolved the issue.
  • Act in good faith. Non-destructive testing only. Cease testing immediately if you encounter real customer data or PII.

4. Scope

  • In-Scope Domains:*.aliengate.io, AlienGate Public APIs, and customer-facing web applications.
  • Out-of-Scope: Third-party vendor services, physical office security, social engineering (phishing), and spamming.

5. How to Report a Vulnerability

Send your findings to security@aliengate.io. Please include:

  1. Detailed description of the vulnerability and potential impact.
  2. Step-by-step proof-of-concept (PoC) or script to reproduce the issue.
  3. Relevant screenshots or HTTP request/response logs.
  4. (Optional) Encryption: Use our PGP Key (0xAG_SECURITY_KEY) for sensitive submissions.

[ Faq ]

Frequently asked questions

Everything you need to know about the product and billing.

Simply sign up with your email and enter your company domain. You can start with a free breach check immediately, and expand to continuous monitoring when ready.

No. AlienGate supports DAST beyond OWASP Top 10, providing comprehensive coverage including network vulnerability scanning capable of detecting 15,000+ CVEs.

AlienGate provides screenshots, port/service details, technology detection, and credential exposure context—giving you the proof needed to validate risks and justify remediation priorities.

Yes. The Investigations feature turns alerts into trackable cases with assigned owners, status tracking, and evidence collection. Reports can be generated for executives and compliance teams.

AI accelerates operations with automated risk scoring, smart summaries of findings, and next-action guidance—helping teams focus on what matters most without manual triage.

Find out what's already out there. It takes about forty seconds.

Run a free exposure check on your domain. If it comes back clean, you've lost a minute. If it doesn't, you've found out before someone else did.