If you have found a security issue in planckdefense.com or in infrastructure we operate, we want to hear about it. Send good-faith reports to security@planckdefense.com. Encrypted mail is welcome, and a PGP key is available on request from the same address.
Email security@planckdefense.com. That address is read by the engineers who run our systems, not a ticket queue, and every report is reviewed by a human. You do not need an account, a form, or a platform profile to reach us.
If you prefer to encrypt, send a plain first message asking for our current PGP key. We will reply with the key and its fingerprint before you share any technical detail, so you can verify what you are encrypting to.
We acknowledge every report within two business days. If the issue is confirmed, we keep you informed through triage and remediation until it is closed.
This policy applies to systems that Planck owns and operates. If you are unsure whether an asset belongs to us, ask before you test. A short email costs nothing and keeps you inside the policy.
Testing under this policy is limited to assets under our direct operational control.
The following are excluded. Testing them is not authorized by this policy under any circumstances.
We will not pursue or support legal action against researchers who discover and report vulnerabilities in our systems in good faith and within the terms of this policy. Research conducted under these terms is authorized activity as far as we are concerned, and we will not refer it to law enforcement. We spend our working lives on the other side of this exchange, reporting vulnerabilities to vendors, and we hold ourselves to the standard we expect from them.
Good faith has a concrete meaning here. It means you access only what is necessary to demonstrate that an issue exists, and nothing more. Specifically, you agree to the following conditions.
On disclosure timing, we ask for coordination rather than silence. Tell us what you found, give us a realistic window to fix it, and we will work with you on when and how details become public. If you are ever unsure whether something you plan to do falls within this policy, write to security@planckdefense.com first and ask. We answer those questions quickly, and asking never counts against you.
A disclosure policy is only as good as the response behind it. This is the sequence every report moves through, handled by engineers rather than a support layer.
You receive a human acknowledgment within two business days, confirming the report arrived and naming the person handling it.
An engineer reproduces the issue, assesses its severity and reach, and comes back to you with questions if anything is unclear.
Confirmed issues are fixed with a priority that matches their severity. We tell you when the fix ships so you can verify it yourself.
If you want recognition, we credit you by name or handle once the issue is resolved. If you prefer anonymity, we respect that without question.
We do not currently run a paid bug bounty program, and we say so plainly so that expectation is set before your report arrives, not after. What we offer instead is a serious response: engineers reading your report, honest communication about severity and timelines, public credit if you want it, and a direct line to the people fixing the issue.
Good reports make our systems better, and we treat the researchers who send them as colleagues. For questions about this policy, or about how we handle data more broadly, get in touch.