Vulnerability disclosure
Last updated 8 September 2026. This is the policy named by security.txt . It covers the ReconSec public site, not client assessments.
Scope
In scope: reconsec.io, www.reconsec.io if it is ever served, and Vercel preview hostnames that clearly belong to this project. Out of scope: client systems, mailboxes, third-party processors, and any host we have not named here.
Rules
Do not DDoS. Do not interrupt service. Do not access other people's data. Do not run automated scanners that flood the origin. Do not demand payment as a condition of telling us. Social engineering of people is out of scope.
Good faith
If you stay inside this policy, we will not pursue a legal complaint against you for that research. We may still involve law enforcement if the activity is extortion, data theft, or service interruption.
How to report
Write to team@reconsec.io with the host, the path, what you observed, and enough to reproduce. We will acknowledge, investigate, and tell you when a fix is live. There is no public bug bounty on this site.