/security
Security Policy
- Version
- v1.1
- Last updated
- 2026-05-06
- Effective date
- 2026-05-06
- Changes
- Full changelog
Report a vulnerability
Found a security issue? Email security@spidyops.com encrypted with our PGP key. Reproduction steps and impact analysis are welcome. We acknowledge every report within 72 hours (see the SLA below).
1. Policy statement
SpidyOps welcomes responsible-disclosure reports from the security community. If you believe you've found a vulnerability in any SpidyOps infrastructure (this site, our web services, or related domains), please report it to security@spidyops.com. PGP encryption is recommended for reports containing credentials, PII, or active session tokens — key fingerprint and public block at the bottom of this page.
2. Safe harbour
We will not pursue legal action against researchers who act in good faith, comply with this policy, avoid privacy violations and service degradation, and give us reasonable time to address the issue before public disclosure. Research conducted within the rules below is considered authorised testing.
3. Scope
spidyops.comand any subdomainspidyops.caand any subdomain (redirect target)- Email infrastructure (DKIM / SPF / DMARC misconfigurations)
4. Out of scope
- Self-XSS
- Missing security headers without demonstrated impact
- Rate-limit issues on public read-only endpoints
- Vulnerabilities in third-party dependencies without a working chain into SpidyOps
- Findings from automated scanners without manual validation
- Vulnerabilities requiring physical access to a victim's device
- Username or email enumeration without further impact
- CSRF on forms with no security impact
- Login/logout CSRF, tabnabbing, clickjacking on pages without sensitive actions
- Lack of CAPTCHA on public endpoints
- Volumetric attacks, spam, or denial-of-service
- Social engineering, physical attacks, or anything targeting personal accounts of operators or staff
5. Testing rules
When conducting authorised testing under this policy:
- Use only accounts you control for testing.
- If you encounter PII or data not your own, stop immediately and report it.
- Rate-limit your scanning — no automated traffic that degrades service.
- No destructive payloads, no exfiltration beyond minimum-needed proof-of-concept.
- No social engineering of operators, users, or third parties.
- Use a research user-agent so we can distinguish research traffic from attacks:
User-Agent: SpidyOps-Research/1.0 (your-handle)
6. Process and SLA
After receiving a report:
- Acknowledgement: within 72 hours.
- Triage decision: within 14 days.
- Fix ETA communicated: within 14 days of triage.
- Public disclosure: coordinated, default 90 days from report.
- CVE co-signing where appropriate.
7. Recognition
SpidyOps does not currently operate a paid bug bounty programme. Recognition is provided through:
- Public credit for coordinated disclosures, with your preferred handle (or anonymous if requested).
- A signed disclosure letter for your portfolio.
- Coordinated CVE assignment where applicable.
- Priority review of future submissions.
A paid bounty programme may be introduced as the platform matures.
8. PGP key
Fingerprint: DA35 104C F168 0A5D 9907 124C 372D 5C34 60AD AF0A
Email: security@spidyops.com
Expires: 2028-05-02
Public key: /keys/security.asc9. Contact
Reports: security@spidyops.com. General security questions: ask@spidyops.com.
10. Versioning
See the full version history at /security/changelog. Material changes are announced via the newsletter and a site banner.