DomainDrift · DRM3 Labs Corp.

Security and vulnerability disclosure

We welcome reports from security researchers. If you have found something, tell us and we will work the issue with you.

Report to security@drm3.io

Include the affected URL or endpoint, what you did, what happened, and enough detail for us to reproduce it. A proof of concept helps. Please give us a way to reach you for follow-up questions.

What we commit to

Safe harbour

If you make a good-faith effort to follow this policy while researching, we will treat your research as authorised. We will not pursue or support legal action against you, and if a third party brings action against you for work that followed this policy, we will make it known that your research was authorised.

Good faith means: you stop as soon as you have demonstrated the issue, you do not access or modify data that is not yours, you do not degrade the service for anyone else, and you give us a reasonable chance to fix the issue before you discuss it publicly.

In scope

Out of scope, and prohibited

The following are not authorised under this policy. Testing them is not covered by the safe harbour above.

Abuse and scanner conduct

If DomainDrift's scanner is reaching your infrastructure and you want it to stop, you do not need to file a security report. Write to security@drm3.io or use the domain opt-out at drm3.io/publisher-opt-out and we will deactivate the domain. We honour 429 and 403 with backoff and we do not attempt to work around blocks.

What a signature does and does not prove

DomainDrift signs its observations so that anyone can confirm the bytes came from us and have not been altered. That is attribution and integrity. It is not a claim that an observation is correct, complete, or legally sufficient for any purpose.