/security

Security Policy

Version
v1.1
Last updated
2026-05-06
Effective date
2026-05-06

Report a vulnerability

Found a security issue? Email security@spidyops.com encrypted with our PGP key. Reproduction steps and impact analysis are welcome. We acknowledge every report within 72 hours (see the SLA below).

1. Policy statement

SpidyOps welcomes responsible-disclosure reports from the security community. If you believe you've found a vulnerability in any SpidyOps infrastructure (this site, our web services, or related domains), please report it to security@spidyops.com. PGP encryption is recommended for reports containing credentials, PII, or active session tokens — key fingerprint and public block at the bottom of this page.

2. Safe harbour

We will not pursue legal action against researchers who act in good faith, comply with this policy, avoid privacy violations and service degradation, and give us reasonable time to address the issue before public disclosure. Research conducted within the rules below is considered authorised testing.

3. Scope

  • spidyops.com and any subdomain
  • spidyops.ca and any subdomain (redirect target)
  • Email infrastructure (DKIM / SPF / DMARC misconfigurations)

4. Out of scope

  • Self-XSS
  • Missing security headers without demonstrated impact
  • Rate-limit issues on public read-only endpoints
  • Vulnerabilities in third-party dependencies without a working chain into SpidyOps
  • Findings from automated scanners without manual validation
  • Vulnerabilities requiring physical access to a victim's device
  • Username or email enumeration without further impact
  • CSRF on forms with no security impact
  • Login/logout CSRF, tabnabbing, clickjacking on pages without sensitive actions
  • Lack of CAPTCHA on public endpoints
  • Volumetric attacks, spam, or denial-of-service
  • Social engineering, physical attacks, or anything targeting personal accounts of operators or staff

5. Testing rules

When conducting authorised testing under this policy:

  • Use only accounts you control for testing.
  • If you encounter PII or data not your own, stop immediately and report it.
  • Rate-limit your scanning — no automated traffic that degrades service.
  • No destructive payloads, no exfiltration beyond minimum-needed proof-of-concept.
  • No social engineering of operators, users, or third parties.
  • Use a research user-agent so we can distinguish research traffic from attacks: User-Agent: SpidyOps-Research/1.0 (your-handle)

6. Process and SLA

After receiving a report:

  • Acknowledgement: within 72 hours.
  • Triage decision: within 14 days.
  • Fix ETA communicated: within 14 days of triage.
  • Public disclosure: coordinated, default 90 days from report.
  • CVE co-signing where appropriate.

7. Recognition

SpidyOps does not currently operate a paid bug bounty programme. Recognition is provided through:

  • Public credit for coordinated disclosures, with your preferred handle (or anonymous if requested).
  • A signed disclosure letter for your portfolio.
  • Coordinated CVE assignment where applicable.
  • Priority review of future submissions.

A paid bounty programme may be introduced as the platform matures.

8. PGP key

Fingerprint: DA35 104C F168 0A5D 9907  124C 372D 5C34 60AD AF0A
Email:       security@spidyops.com
Expires:     2028-05-02
Public key:  /keys/security.asc

9. Contact

Reports: security@spidyops.com. General security questions: ask@spidyops.com.

10. Versioning

See the full version history at /security/changelog. Material changes are announced via the newsletter and a site banner.