PSIRT · RESPONSIBLE DISCLOSURE

We hold ourselves to the standard we sell.

How threatDefendr secures its own platform, and how researchers can report a vulnerability — with a clear policy, safe harbor, and a bounty for the people who help keep us honest.

OUR PRACTICES

Security is the product — and the posture.

Encryption everywhere

TLS 1.3 in transit, AES-256 at rest, and customer-managed keys for tenant data.

Secure SDLC

Threat modeling, SAST/DAST/SCA in CI, and signed, provenance-tracked artifacts.

Continuous testing

Independent annual pen tests, an internal red team, and an always-on bug bounty.

Least privilege

Zero-trust internal access, hardware MFA, and just-in-time grants on production.

RESPONSIBLE DISCLOSURE

Report in good faith. We'll act in good faith.

01
Safe harbor

Good-faith research under this policy is authorized — we will not pursue legal action.

02
Fast triage

We acknowledge within 2 business days and assign a severity and owner.

03
Coordinated timeline

We aim to remediate and coordinate public disclosure within 90 days.

/.well-known/security.txtSIGNED
Contact: mailto:security@threatdefendr.com
Encryption: https://threatdefendr.com/pgp.txt
Policy: https://threatdefendr.com/security
Acknowledgments: /security/hall-of-fame
Preferred-Languages: en
Expires: 2027-01-01T00:00:00Z
PGP · 3F9A 7C21 0E44 9B05 · 4096R
BUG BOUNTY

Paid for what you find.

Rewards scale with impact, validated against CVSS and real-world exploitability.

SEVERITYEXAMPLEREWARD
CriticalRCE, auth bypass, cross-tenant data access$15k – $50k
HighPrivilege escalation, stored XSS, SSRF$5k – $15k
MediumCSRF, IDOR with limited impact$1k – $5k
LowBest-practice and hardening findings$250 – $1k
PSIRT · RESPONSIBLE DISCLOSURE

We hold ourselves to the standard we sell.

How threatDefendr secures its own platform, and how researchers can report a vulnerability — with a clear policy, safe harbor, and a bounty for the people who help keep us honest.

// OUR PRACTICES

Security is the product — and the posture.

Encryption everywhere

TLS 1.3 in transit, AES-256 at rest, and customer-managed keys for tenant data.

Secure SDLC

Threat modeling, SAST/DAST/SCA in CI, and signed, provenance-tracked artifacts.

Continuous testing

Independent annual pen tests, an internal red team, and an always-on bug bounty.

Least privilege

Zero-trust internal access, hardware MFA, and just-in-time grants on production.

// RESPONSIBLE DISCLOSURE

Report in good faith. We'll act in good faith.

01
Safe harbor

Good-faith research under this policy is authorized — we will not pursue legal action.

02
Fast triage

We acknowledge within 2 business days and assign a severity and owner.

03
Coordinated timeline

We aim to remediate and coordinate public disclosure within 90 days.

/.well-known/security.txtSIGNED
Contact: mailto:security@threatdefendr.com
Encryption: https://threatdefendr.com/pgp.txt
Policy: https://threatdefendr.com/security
Acknowledgments: /security/hall-of-fame
Preferred-Languages: en
Expires: 2027-01-01T00:00:00Z
PGP · 3F9A 7C21 0E44 9B05 · 4096R
// BUG BOUNTY

Paid for what you find.

Rewards scale with impact, validated against CVSS and real-world exploitability.

SEVERITYEXAMPLEREWARD
CriticalRCE, auth bypass, cross-tenant data access$15k – $50k
HighPrivilege escalation, stored XSS, SSRF$5k – $15k
MediumCSRF, IDOR with limited impact$1k – $5k
LowBest-practice and hardening findings$250 – $1k