Skip to content
Back to security
Disclosure policy
Security practice

Vulnerability disclosure policy

This policy covers internet-accessible systems owned and operated by Mach 1 Consulting. Third-party services are governed by their providers' policies. If you are unsure whether an asset is in scope, contact us before testing.
Document
Scope
Mach 1 owned systems
Acknowledgement
3 business days
Bounty
Not offered
Encryption
PGP available
Working
agreement

What to expect

  • We aim to acknowledge reports within three business days.
  • We will validate the issue and coordinate remediation in good faith.
  • We will share meaningful progress when it is available.
  • We will discuss disclosure timing before report details are published.

What we ask

  • Avoid privacy violations, disruption, denial of service, and social engineering.
  • Stop after proving impact; do not retain, alter, or destroy data.
  • Do not run high-volume automated testing without prior coordination.
  • Allow a reasonable opportunity to investigate and remediate before disclosure.
Security
contact

Send a minimal initial report

Email nyxxthewolf@gmail.com. For sensitive details, use the public key and verify its fingerprint against the value published on the security page.

Mach 1 Consulting does not currently operate a bug-bounty program or promise payment for reports.