Spiral Sentinel Labs Disclosure perimeter

Reporting channel open

Public security channel / perimeter 01

Find the fault. Respect the boundary.

Spiral Sentinel Labs welcomes careful, reproducible reports about security issues on surfaces we operate and access paths you are already authorized to use.

Responsible disclosure channel. No public bounty program, guaranteed response time, or promise of compensation.

Perimeter state Bounded / listening Observe openly routed surfaces. Stop before private data or private systems.
Contact
security@spiralsentinel.com
Scope
Public + authorized
Testing
Manual + low volume
Program
Disclosure, no bounty

Scope map / 02

Test the surface.
Not the people behind it.

Public reachability does not make every action authorized. Keep work narrow, non-destructive, and tied to a clear security question.

Inside perimeter

Allowed

Careful public-surface testing.

  • Static pages, public assets, response headers, and routing.
  • DNS, DNSSEC, TLS, DANE/TLSA, and signed security.txt behavior.
  • Publicly reachable client endpoints and login surfaces.
  • Invite-only service behavior using only your own authorized account.
  • Minimal proofs that stop once the issue is demonstrated.

Outside perimeter

Do not attempt

No private-system access.

  • Other users, credentials, sessions, private documents, or personal data.
  • Administrative panels, non-public APIs, local devices, or the private S1M4X core.
  • Authentication bypass, brute force, phishing, or social engineering.
  • Denial of service, high-volume scanning, persistence, malware, or destructive tests.
  • Testing third-party providers or infrastructure we do not control.

Signal format / 03

Make the report reproducible.

A compact, well-redacted report is more useful than a large scan dump. Include enough evidence to confirm the issue without carrying unrelated data.

  1. 01
    Affected coordinate

    The URL, hostname, endpoint, or public record involved.

  2. 02
    Security impact

    What could happen, who could be affected, and why it matters.

  3. 03
    Reproduction path

    Minimal ordered steps, expected behavior, and actual behavior.

  4. 04
    Environment

    Relevant browser, client, tool, operating system, and version details.

  5. 05
    Redacted evidence

    Small request examples or screenshots with tokens and personal data removed.

Stop condition / 04

Encountered private data? Stop.

Do not copy, alter, retain, or share it. Record only the minimum context needed to identify the affected route, close the session, and contact the security inbox. Never send live passwords, access tokens, recovery keys, or unredacted personal data by email.

Verified route / 05

One reporting path.

The signed security record publishes the canonical disclosure page and contact route. Privacy questions remain separate.