Security

    Responsible Disclosure

    We take security seriously. If you've discovered a vulnerability, we want to hear from you.

    How to Report

    Please send your findings to security@nineowls.com with a detailed description of the vulnerability. Include steps to reproduce, potential impact, and any supporting evidence (screenshots, logs, proof-of-concept).

    We aim to acknowledge reports within 48 hours and provide a resolution timeline within 5 business days.

    Guidelines

    Provide a detailed description of the vulnerability, including steps to reproduce.

    Allow us reasonable time to investigate and address the issue before disclosing it publicly.

    Do not access, modify, or delete data belonging to other users or clients.

    Do not perform actions that could degrade the performance or availability of our services.

    Do not use automated scanning tools that generate excessive traffic.

    Act in good faith and avoid any actions that violate applicable laws.

    In Scope

    nineowls.com and all associated subdomains

    Client-facing web applications

    APIs and backend services

    Authentication and authorization mechanisms

    Out of Scope

    Social engineering or phishing attacks against employees or clients

    Physical security testing

    Denial of service (DoS/DDoS) attacks

    Findings from automated vulnerability scanners without manual verification

    Issues in third-party services or applications not controlled by NineOwls

    Safe Harbor

    NineOwls Consulting Group will not pursue legal action against security researchers who discover and report vulnerabilities in good faith, in accordance with these guidelines. We consider responsible security research conducted consistent with this policy to be authorized, and we will work with you to understand and resolve issues quickly.