1. Our Commitment to Security
At AlienGate, the security of our platform and customer data is paramount. We value the contributions of the independent security research community and encourage responsible reporting of potential vulnerabilities.
2. Safe Harbor Agreement
If you conduct security research and report vulnerabilities in compliance with this policy:
- We will not pursue legal action against you.
- We will work with you to understand and validate your findings.
- We will recognize your contribution if you are the first to report a confirmed issue.
3. Rules of Engagement
To qualify for Safe Harbor, researchers must strictly adhere to the following rules:
- Do not access or modify customer data. Test only using your own accounts or authorized test environments.
- Avoid service disruption. Do not perform Denial of Service (DoS/DDoS), spamming, or brute-force attacks against AlienGate systems.
- Maintain confidentiality. Do not disclose vulnerability details publicly until AlienGate has validated and resolved the issue.
- Act in good faith. Non-destructive testing only. Cease testing immediately if you encounter real customer data or PII.
4. Scope
- In-Scope Domains:
*.aliengate.io, AlienGate Public APIs, and customer-facing web applications. - Out-of-Scope: Third-party vendor services, physical office security, social engineering (phishing), and spamming.
5. How to Report a Vulnerability
Send your findings to security@aliengate.io. Please include:
- Detailed description of the vulnerability and potential impact.
- Step-by-step proof-of-concept (PoC) or script to reproduce the issue.
- Relevant screenshots or HTTP request/response logs.
- (Optional) Encryption: Use our PGP Key (
0xAG_SECURITY_KEY) for sensitive submissions.