Security
Responsible Disclosure
We do offensive security for a living. If you find something on endescope.com, you get a fast response, credit, and a Hall of Thanks mention where appropriate.
Scope
All assets under *.endescope.com are in scope. Third-party services (hosting infrastructure, email providers, etc.) are out of scope; please report those directly to the vendor.
Exclusions
- Automated scans without manual validation
- SPF/DMARC/DKIM configuration notes (handled separately)
- Missing security headers without a concrete exploit
- Rate-limit complaints on public static assets
- Self-XSS, clickjacking without demonstrated impact
- Denial of service
Reporting
Email security@endescope.com with vulnerability details, reproducible steps, and optionally a PoC. A PGP key for encrypted communication will launch with the phase-two version of this site.
Our commitment
- Response within 24 hours on business days
- Status update every 72 hours until resolution
- Safe harbor: we do not pursue security research conducted in good faith
- Hall of Thanks credit (if desired)
No bounties yet, but
We currently do not pay monetary bounties on endescope.com itself. For critical findings we send a token of thanks (swag, reference letter, networking) and offer prominent Hall of Thanks placement.
Last updated: 2026-04-22