We take security seriously. If you've discovered a vulnerability, we want to hear from you.
Please send your findings to security@nineowls.com with a detailed description of the vulnerability. Include steps to reproduce, potential impact, and any supporting evidence (screenshots, logs, proof-of-concept).
Provide a detailed description of the vulnerability, including steps to reproduce.
Allow us reasonable time to investigate and address the issue before disclosing it publicly.
Do not access, modify, or delete data belonging to other users or clients.
Do not perform actions that could degrade the performance or availability of our services.
Do not use automated scanning tools that generate excessive traffic.
Act in good faith and avoid any actions that violate applicable laws.
nineowls.com and all associated subdomains
Client-facing web applications
APIs and backend services
Authentication and authorization mechanisms
Social engineering or phishing attacks against employees or clients
Physical security testing
Denial of service (DoS/DDoS) attacks
Findings from automated vulnerability scanners without manual verification
Issues in third-party services or applications not controlled by NineOwls
NineOwls Consulting Group will not pursue legal action against security researchers who discover and report vulnerabilities in good faith, in accordance with these guidelines. We consider responsible security research conducted consistent with this policy to be authorized, and we will work with you to understand and resolve issues quickly.