DomainDrift · DRM3 Labs Corp.
Security and vulnerability disclosure
We welcome reports from security researchers. If you have found something, tell us and we will work the issue with you.
Include the affected URL or endpoint, what you did, what happened, and enough detail for us to reproduce it. A proof of concept helps. Please give us a way to reach you for follow-up questions.
What we commit to
- We acknowledge a report within 3 business days.
- We give you an initial assessment, including severity, within 10 business days.
- We keep you updated while we work the fix, and we tell you when it ships.
- We credit you publicly if you want the credit, and stay quiet about you if you do not.
Safe harbour
If you make a good-faith effort to follow this policy while researching, we will treat your research as authorised. We will not pursue or support legal action against you, and if a third party brings action against you for work that followed this policy, we will make it known that your research was authorised.
Good faith means: you stop as soon as you have demonstrated the issue, you do not access or modify data that is not yours, you do not degrade the service for anyone else, and you give us a reasonable chance to fix the issue before you discuss it publicly.
In scope
domaindrift.ioand its API under/connor/v1/*- The signed receipt and provenance surfaces, including the key registry at
/.well-known/domaindrift-keys.json - Authentication, session handling, and the entitlement or metering boundary
- Webhook delivery and any server-side request handling
Out of scope, and prohibited
The following are not authorised under this policy. Testing them is not covered by the safe harbour above.
- Denial of service, load testing, resource exhaustion, or anything that degrades availability for other users
- Social engineering, phishing, or physical attacks against DRM3 staff, users, or vendors
- Accessing, modifying, exfiltrating, or destroying data belonging to anyone but you. If you encounter someone else's data, stop and tell us
- Attacks against our third-party vendors, or against domains that DomainDrift scans. Those domains are not ours and we cannot authorise testing against them
- Automated scanning that generates high request volume, spam, or noise
- Reports produced solely by an automated tool with no demonstrated impact
- Missing hardening headers, or a weak cipher suite, with no demonstrated exploit path
Abuse and scanner conduct
If DomainDrift's scanner is reaching your infrastructure and you want it to stop, you do
not need to file a security report. Write to security@drm3.io or use
the domain opt-out at drm3.io/publisher-opt-out
and we will deactivate the domain. We honour 429 and 403 with backoff
and we do not attempt to work around blocks.
What a signature does and does not prove
DomainDrift signs its observations so that anyone can confirm the bytes came from us and have not been altered. That is attribution and integrity. It is not a claim that an observation is correct, complete, or legally sufficient for any purpose.