BlackDogs CSIRT · Policy
Coordinated Vulnerability Disclosure Policy
BlackDogs Security welcomes reports from security researchers who identify vulnerabilities in our infrastructure and services. This policy explains what is in scope, how to report, what we commit to in return, and the protections available to researchers acting in good faith.
- Version
- 1.0 — 11 September 2026
- Reports to
- [email protected]
- Encryption
- PGP key 0x881C5CE5806EE9B3
- Languages
- English · Spanish · Catalan
1. Scope
This policy covers systems and services operated by BlackDogs Security under its own responsibility:
- Domains and subdomains of
blackdogs.io. - Public-facing infrastructure, applications and APIs operated by BlackDogs Security.
- Software and configurations published by BlackDogs Security.
Reports concerning the infrastructure of a BlackDogs customer are also welcome, but BlackDogs CSIRT cannot authorise testing against systems it does not own. In those cases the team will act as coordinator between the reporter and the affected organization, and will not disclose the customer's identity without that customer's consent.
2. Out of scope
The following are generally not treated as reportable vulnerabilities under this policy:
- Findings from automated scanners without a demonstrated, exploitable impact.
- Missing security headers, cookie flags or TLS configuration preferences with no demonstrated exploitation path.
- Reports of outdated software versions without a working proof of concept against our systems.
- Social engineering, phishing or physical attacks against BlackDogs staff, customers or premises.
- Denial of service, volumetric testing, brute force, or anything degrading availability for others.
- Vulnerabilities requiring a rooted or compromised device, or physical access to a user's machine.
- Self-XSS, clickjacking on pages with no sensitive action, and issues requiring unlikely user interaction.
- Third-party services BlackDogs merely consumes. Report those to the vendor; we will help coordinate if the impact reaches us.
If you believe a finding in this list has real impact in our specific context, send it anyway and explain why.
3. How to report
Send your report by email to [email protected]. Encrypt anything sensitive with the BlackDogs CSIRT PGP key — fingerprint 05D9 A242 CE24 E6D0 13F2 A060 881C 5CE5 806E E9B3.
A useful report includes:
- The affected asset: URL, hostname, IP or component.
- Vulnerability type and a clear description of the issue.
- Reproduction steps, or a minimal proof of concept.
- The impact you believe it has, and any prerequisites for exploitation.
- Date and time of testing, and the source IP you tested from, so we can distinguish your activity from a real attack.
- How you would like to be credited, if at all.
- A TLP designation if you have handling requirements.
Do not include passwords, private keys, personal data of third parties or customer data in your report beyond the minimum needed to demonstrate the issue.
4. Research conducted in good faith
Testing is considered good faith when it stays within the limits below.
Permitted
- Accessing only data that belongs to you, or to a test account you created.
- Using the minimum interaction necessary to confirm a vulnerability exists.
- Stopping as soon as access is confirmed, rather than exploring further.
- Reporting promptly and giving us reasonable time to remediate.
Not permitted
- Accessing, modifying, downloading or retaining data belonging to other people.
- Degrading, interrupting or denying service, including load and stress testing.
- Persisting access, installing backdoors, or pivoting to other systems.
- Modifying or destroying data, or making changes visible to other users.
- Exfiltrating credentials, keys or customer information.
- Publicly disclosing the issue before the coordination process has concluded.
- Demanding payment in exchange for disclosing a vulnerability. BlackDogs does not operate a bug bounty programme and does not pay for reports.
5. Handling of data encountered
If your testing exposes personal data, credentials or confidential information, stop immediately, do not retain or copy it, and say so in your report. Describe what you saw without reproducing the data itself.
BlackDogs CSIRT handles disclosure reports on a need-to-know basis, under the Traffic Light Protocol (TLP) 2.0, and applies the same information-handling controls described in the RFC 2350 team description. Your identity and contact details are not shared outside the handling of the report without your consent, except where disclosure is required by law.
6. What you can expect from us
- Acknowledgement of your report, within the response targets published on the BlackDogs CSIRT page.
- An initial assessment — whether we consider the report in scope and valid — within 10 business days.
- Progress updates at reasonable intervals while remediation is under way, and on request.
- Notification when the issue is resolved, or an explanation if we decide not to act on it.
- Coordination with the affected party if the report concerns a customer or a third-party vendor.
- Credit as described in section 9, if you want it.
7. Coordinated disclosure timeline
BlackDogs CSIRT aims to remediate valid vulnerabilities within 90 days of the report, and asks researchers not to disclose publicly before that period has elapsed or remediation is complete, whichever comes first.
Where a fix is genuinely complex, we may ask for an extension, explaining why and giving a revised date. Where a vulnerability is being actively exploited, we may act and communicate faster.
We prefer coordinated publication and are happy to agree a joint disclosure date, to review a draft advisory for factual accuracy, and to request a CVE where appropriate. We will not ask you to keep a resolved issue secret indefinitely.
8. Safe harbour
BlackDogs Security will not initiate or support legal action against researchers who act in good faith and in accordance with this policy.
We consider such research to be authorised conduct, and we will not report it to law enforcement as an attack. If a third party brings action against you for research you carried out within this policy, we will make it known that your activity was conducted in accordance with it.
This protection covers only systems within the scope of section 1, and only conduct within the limits of section 4. It does not extend to testing against customer systems without that customer's authorisation, and it cannot override obligations BlackDogs Security has under applicable law.
If you are unsure whether a specific action is covered, ask us first at [email protected] before performing it.
9. Recognition
BlackDogs does not operate a bug bounty programme and does not offer monetary rewards. We do offer credit: with your permission, we will acknowledge your contribution when the issue is disclosed, using the name or handle you prefer. You may also ask to remain anonymous.
10. Changes to this policy
This is version 1.0, dated 11 September 2026. The current version is always published at https://blackdogs.io/csirt/vulnerability-disclosure and referenced from /.well-known/security.txt in accordance with RFC 9116.
Spanish and Catalan translations are available at /csirt/vulnerability-disclosure/es and /csirt/vulnerability-disclosure/ca. In case of discrepancy, the English version prevails.