Security disclosure policy

Report security issues responsibly.

Effective August 12, 2026
Policy owner: Apogee1 LLC

Apogee1 welcomes clear, good-faith reports of suspected security vulnerabilities affecting systems and services that we own or operate.

Purpose

This policy defines how external researchers, customers, partners, and others can report a suspected Apogee1 security vulnerability. It is a reporting channel, not a bug-bounty program or authorization to test any system.

Reporting a vulnerability

Email contact@apogee1.net with “Security report” in the subject. Include the affected system or URL, reproduction steps, potential impact, and the minimum evidence needed for triage. Do not include credentials, secrets, or personal data in the initial report.

Scope

Reports should concern systems, applications, APIs, data paths, or public-facing assets owned or operated by Apogee1 LLC. This policy does not grant authorization to test Apogee1, ShadowLines, portfolio companies, customers, service providers, or other third parties. Test only systems you own or are explicitly authorized to assess.

Researcher expectations

Avoid privacy impact, destructive testing, service disruption, social engineering, spam, credential attacks, persistence, or access to data that is not your own. Stop testing and report promptly if you encounter sensitive data or an unexpected impact. Do not publicly disclose a suspected issue before we have had a reasonable opportunity to investigate and coordinate remediation.

Safe harbor

Apogee1 will not pursue legal action for testing that was authorized, performed in good faith, stayed within that authorization and this policy, and avoided privacy impact or service disruption. This statement does not grant authorization, waive the rights of third parties, or excuse conduct that violates law or an agreement.

Response commitments

We review complete reports, triage potential impact, validate issues we can reproduce, and communicate through remediation when a report is accepted. Response and remediation timing depends on severity, complexity, and the systems involved; this policy does not promise a fixed service level.

Coordinated disclosure

If public disclosure is appropriate, we ask reporters to coordinate timing and technical detail with Apogee1 so affected parties have a reasonable opportunity to remediate and sensitive information is not exposed unnecessarily.

Contact

Send security reports to contact@apogee1.net. Machine-readable contact information is available in security.txt. See also our Responsible Security principles and Privacy Policy.