Skip to main content

Policy

Responsible Disclosure

Last updated: June 2026

Stealth Layer Security takes the security of its website, systems, and services seriously. This policy explains how security concerns may be reported to us and sets clear boundaries around unauthorized testing.

No Public Bug Bounty or Authorization to Test

Stealth Layer Security does not operate a public bug bounty program.

This policy does not grant permission to perform security testing, vulnerability scanning, automated probing, exploitation, social engineering, denial-of-service testing, credential attacks, or any activity intended to identify or validate vulnerabilities in Stealth Layer Security systems, websites, infrastructure, accounts, or services.

Any security testing of Stealth Layer Security assets requires prior written authorization from Stealth Layer Security.

Scope

This policy applies only to security concerns related to systems owned and operated by Stealth Layer Security, including the stealthlayersecurity.com website.

This policy does not authorize testing of client systems, third-party services, vendors, hosting providers, email systems, cloud services, or any infrastructure not directly owned and operated by Stealth Layer Security.

How to Report a Security Concern

If you believe you have discovered a security issue through normal, good-faith use of our website or services, please report it to:

security@stealthlayersecurity.com

Please include:

  • A clear description of the issue
  • The affected URL or component
  • Steps to reproduce, where applicable
  • Relevant screenshots or supporting evidence
  • Your contact information for follow-up

Do not include, access, download, modify, retain, or disclose sensitive data beyond what is strictly necessary to describe the concern.

Prohibited Activities

The following activities are not authorized:

  • Automated vulnerability scanning or crawling
  • Exploitation of vulnerabilities
  • Attempts to access, modify, delete, or exfiltrate data
  • Testing against accounts, systems, or data that do not belong to you
  • Denial-of-service, stress testing, or activity that may affect availability
  • Social engineering, phishing, impersonation, or physical attacks
  • Credential attacks, password spraying, brute forcing, or session abuse
  • Testing of third-party systems, client environments, vendors, or service providers
  • Public disclosure of a suspected vulnerability before Stealth Layer Security has reviewed and addressed it

Our Response

We will review good-faith reports submitted through the proper channel and may contact the reporter for clarification.

Submission of a report does not create a service relationship, employment relationship, bounty entitlement, payment obligation, or authorization to conduct further testing.

Stealth Layer Security does not guarantee compensation, public recognition, or credit for submitted reports.

Safe Harbor Limitation

Because Stealth Layer Security does not operate a public bug bounty program, this policy does not provide blanket safe harbor for unsolicited testing.

Reports made in good faith through normal use of our website may be reviewed responsibly. However, activity involving unauthorized testing, scanning, exploitation, data access, service disruption, or third-party systems may be treated as unauthorized activity.

Contact

Security concerns may be reported to:

security@stealthlayersecurity.com