Spiral Sentinel Labs welcomes careful, reproducible reports about
security issues on surfaces we operate and access paths you are
already authorized to use.
Responsible disclosure channel. No public bounty program, guaranteed
response time, or promise of compensation.
RPublic edgeAuthorized pathPrivate core
Perimeter stateBounded / listening
Observe openly routed surfaces. Stop before private data or private systems.
Contact
security@spiralsentinel.com
Scope
Public + authorized
Testing
Manual + low volume
Program
Disclosure, no bounty
Scope map / 02
Test the surface. Not the people behind it.
Public reachability does not make every action authorized. Keep work
narrow, non-destructive, and tied to a clear security question.
Inside perimeter
Allowed
Careful public-surface testing.
Static pages, public assets, response headers, and routing.
DNS, DNSSEC, TLS, DANE/TLSA, and signed security.txt behavior.
Publicly reachable client endpoints and login surfaces.
Invite-only service behavior using only your own authorized account.
Minimal proofs that stop once the issue is demonstrated.
Outside perimeter
Do not attempt
No private-system access.
Other users, credentials, sessions, private documents, or personal data.
Administrative panels, non-public APIs, local devices, or the private S1M4X core.
Authentication bypass, brute force, phishing, or social engineering.
Denial of service, high-volume scanning, persistence, malware, or destructive tests.
Testing third-party providers or infrastructure we do not control.
Signal format / 03
Make the report reproducible.
A compact, well-redacted report is more useful than a large scan dump.
Include enough evidence to confirm the issue without carrying unrelated data.
01
Affected coordinate
The URL, hostname, endpoint, or public record involved.
02
Security impact
What could happen, who could be affected, and why it matters.
03
Reproduction path
Minimal ordered steps, expected behavior, and actual behavior.
04
Environment
Relevant browser, client, tool, operating system, and version details.
05
Redacted evidence
Small request examples or screenshots with tokens and personal data removed.
Stop condition / 04
Encountered private data? Stop.
Do not copy, alter, retain, or share it. Record only the minimum context
needed to identify the affected route, close the session, and contact the
security inbox. Never send live passwords, access tokens, recovery keys,
or unredacted personal data by email.
Verified route / 05
One reporting path.
The signed security record publishes the canonical disclosure page
and contact route. Privacy questions remain separate.