A stranger reported a vulnerability: a response plan

An email arrives from someone you do not know: they found a vulnerability in your product. What to do in the first hour, the first day and the first week.

Published4 min read

The message usually arrives at the wrong address: support, sales, the personal inbox of the founder. It says that the sender found a vulnerability in your product. Sometimes it includes details, sometimes it asks whether you have a bug bounty program, sometimes it mentions money in the first line.

What you do next decides two things: whether this vulnerability gets fixed quietly, and whether the next researcher writes to you or about you.

Who writes such messages

  • Researchers acting in good faith. They found something, often by accident or while testing a whole class of products, and want it fixed. Many hope for a reward or an acknowledgement; few insist.
  • Reporters of automated findings. A scanner found a missing header or an outdated library, and the report was sent to hundreds of companies. The finding may be real and is usually minor.
  • Extortionists. The message contains a threat: pay, or the data is published. This is a crime and is handled as an incident, not as a report.

From the first message you often cannot tell which one you have. The plan below works for all three until you can.

The first hour

  1. Do not reply in anger and do not threaten. A threat of legal action turns a private report into a public story.
  2. Do not pay and do not promise payment. You do not know yet what you would be paying for.
  3. Do not click links and do not open attachments from the message on a work machine. Pass it to whoever handles security.
  4. Tell the person responsible for security. If nobody is, that is the first finding.

The first day

Acknowledge receipt. Two sentences are enough: the report has been received, it is being examined, and this is the person to talk to. Silence is what makes researchers go public.

Ask for the details, through a channel you control. A dedicated mailbox, ideally with an encryption key. Ask for the affected address, the steps to reproduce and what the reporter was able to access.

Verify on your side. Reproduce the issue yourself, in a test environment if possible. Look at the logs for the period the reporter names: what was accessed, from where, how often. The logs tell you whether the reporter stopped at the proof.

The first week

Assess the severity. What can an attacker do with it, and how hard is it? A CVSS score gives a common language for the answer.

Decide whether it is an incident. If the vulnerability gave access to personal data and you cannot rule out that it was used, the notification duties of data protection law may apply, with short deadlines. This is a question for your lawyers on the first day, not the last.

Fix, then tell the reporter. Say what was fixed and when. If you disagree with the report, say so and explain why.

Thank them. A public acknowledgement, with the consent of the reporter, costs nothing. A reward is your decision; if you pay one, pay it for the finding and not under pressure, and say that it is voluntary.

When money is mentioned first

A researcher who asks whether you have a bounty program is asking a normal question. The answer can be “no, but we are grateful for the report”.

A sender who refuses to give any detail before payment, sets a deadline or threatens publication of data is not reporting a vulnerability. Preserve the messages, do not negotiate alone, involve your lawyers and consider involving law enforcement.

So that the next report arrives properly

The report went to the wrong inbox because there was no right one. Three things fix that:

  • A disclosure policy on your website: what may be tested, how to report, what the reporter can expect, and your commitment not to pursue people who follow the rules.
  • A security.txt file at /.well-known/security.txt, the place where researchers look first. RFC 9116 requires two fields, Contact and Expires; after the date in Expires the file is considered stale.
  • A process behind the mailbox: who reads it, who verifies, who decides, within what time.

This is what a vulnerability disclosure program consists of. If a report is waiting for an answer right now, send us a request and say so: such requests are answered first.

Request

Tell us what needs testing

  • Website check free of charge
  • Reply within 1 business day
  • NDA before any technical detail
  • Fixed price for paid engagements
  • No obligation

Request an assessment

Describe the systems and the goal. A manager replies within 1 business day with clarifying questions and the next step.

Who to reply to

We reply to this address unless you choose another channel.

A sole proprietor writes their own name.

Preferred channel
What to assess
Services of interest

Choose all that apply.

Free check

We check your website free of charge

If we find no problems, you receive the report free of charge as well. You pay for the report only when we find problems, and its price depends on their number and severity.

Terms of the free website security check

Application security

Infrastructure and cloud

Adversary simulation

AI, Web3 and cryptography

Programs and assurance

Application security

Free website security check

We look at your website from the outside, the way an attacker does, and check whether it can be broken into: weak settings, outdated software, exposed files, unsafe forms. The check is free of charge.

Application security

Web application penetration testing

We try to break into your web application the way a real attacker would: log in to the accounts of other people, read the data of other customers, change prices or orders. You learn what is possible before criminals do.

Application security

API security testing

An API is the channel through which your app, your website and your partners exchange data with your servers. We check that nobody can use it to read or change data that is not theirs.

Application security

Mobile application penetration testing

We examine your iOS or Android app and the servers behind it: what the app keeps on the phone, what can be extracted from it and whether its requests can be tampered with.

Application security

Secure code review

Our specialists read the source code of your product and find the mistakes that lead to a break-in, including those that cannot be seen from the outside.

Infrastructure and cloud

Cloud & Kubernetes security assessment

We check how your cloud is set up (AWS, Azure, Google Cloud, Kubernetes): who has access to what, which data is open to the internet and how far an attacker gets after the first mistake.

Infrastructure and cloud

Infrastructure penetration testing

We test your servers and your office network from the outside and from the inside: can an attacker get in, and once inside, reach the accounting system, the mail or the backups.

Infrastructure and cloud

External attack surface assessment

We find everything your company exposes to the internet, including what has been forgotten: old websites, test servers, leaked passwords. Then we show which of it can be attacked.

Infrastructure and cloud

CI/CD & supply chain security

We check the path your code takes from the developer to the customer: build servers, third-party libraries, access keys. Whoever controls that path controls your product.

Adversary simulation

Red team operations

A full-scale exercise. Our team plays a real attacker with a goal, for example to reach customer data, and you see whether your defence notices and stops it.

Adversary simulation

Purple team exercises

Our attackers and your defenders work side by side: we show an attack technique, your team checks whether it sees it, and the gaps in monitoring are closed on the spot.

Adversary simulation

Social engineering assessment

We test people, not machines: the phishing emails, calls and messages that attackers use to obtain passwords. You learn how many employees would be deceived and what to train.

AI, Web3 and cryptography

AI & LLM security testing

If your product has a chatbot or another AI model, we check whether it can be talked into revealing confidential data, breaking its own rules or acting on behalf of someone else.

AI, Web3 and cryptography

Smart contract audit

Before a smart contract holds money, we look for mistakes in its code that would let someone withdraw or freeze the funds. After deployment such mistakes cannot be corrected.

AI, Web3 and cryptography

Cryptography review

We check how your product encrypts data and protects keys: whether the right algorithms are chosen and whether they are applied correctly. A mistake here makes the encryption useless.

Programs and assurance

Bug bounty program management

A bug bounty is a program in which independent researchers look for vulnerabilities in your product and are paid for each one they find. We launch and run such a program for you.

Programs and assurance

Vulnerability disclosure program (VDP)

A public page and a procedure that tell researchers how to report a vulnerability to you safely. Without them reports get lost or arrive as threats. We set the process up and handle incoming reports.

Programs and assurance

Continuous penetration testing

Instead of one test a year, we test every significant change of your product throughout the year, so that a new vulnerability does not wait for months to be found.

Programs and assurance

Compliance-driven penetration testing

A penetration test arranged so that an auditor, a regulator or a large customer accepts its report: PCI DSS, DORA, NIS2, ISO/IEC 27001, SOC 2.

Services of interest

Not sure yet

Choose this if you do not know which service you need. Describe the task in your own words, and a specialist will suggest the service in the reply.

Domain or URL of the website or of the main system to test, for example app.example.com.

What needs testing, why now, and any deadline or compliance requirement. No passwords, keys or vulnerability details.

Confirmations

Do not send credentials, keys or details of a vulnerability through this form. A secure channel is agreed after the first reply.

Automated abuse check