Security
Responsible Disclosure
Found a vulnerability in our properties or product? We want to hear from you.
Last updated: August 2026
1. Our Commitment
We build offensive security tooling — we hold our own properties to the standard we sell. If you discover a vulnerability in redtesters.com or in RedStrike, we will work with you in good faith to understand and resolve it quickly.
2. Scope
- In scope: redtesters.com and its subdomains, this website's infrastructure, and vulnerabilities in the RedStrike product itself.
- Out of scope: third-party services we rely on (GitHub Pages, Web3Forms, Google Fonts) — report those to the respective vendor. Vulnerabilities in systems you scan with RedStrike are your responsibility to report to their owners.
3. How to Report
Email contact@redtesters.com with:
- A clear description of the vulnerability and its impact
- Step-by-step reproduction instructions or a proof of concept
- Affected URLs, endpoints, or components
- Your contact details (and optional attribution name for recognition)
Please do not open public issues or disclose findings before we publish a fix.
4. Safe Harbor
We will not pursue legal action against researchers who: test only in-scope properties, use non-destructive methods, avoid privacy violations and service degradation, stop and contact us immediately upon discovering a critical issue, and report findings in good faith through this program.
5. Response Timelines
- Acknowledgement — within 2 business days
- Initial triage & severity assessment — within 7 days
- Remediation target — Critical: 30 days; High: 60 days; Medium/Low: 90 days
- Coordinated disclosure — jointly agreed; default 90 days from first report
6. Out of Scope
- Denial of service, resource exhaustion, or spam
- Social engineering, phishing, or physical attacks
- Automated scanner output without a working proof of concept
- Missing security headers or best-practice findings without demonstrated impact
- Self-XSS and logout CSRF
7. Recognition
With your permission, we credit researchers who report valid issues — in our release notes and on this page. We do not currently operate a paid bounty program.
8. Machine-Readable Policy
Our security policy is also published at /.well-known/security.txt per RFC 9116.