Effective August 11, 2026
Apogee1 develops defensive cybersecurity products and conducts research to help owners and operators understand and reduce risk. These are our public operating principles—not a certification or a claim of approval by any vendor or access program.
Authorization and scope
We perform security testing only against systems, applications, accounts, networks, and data that Apogee1 owns or operates, or for which we have explicit authorization. Work is scoped before testing. If a finding or action crosses that scope, testing stops until authorization is clear.
Defensive purpose
Our research and tooling are intended for asset visibility, exposure analysis, product security, validation, system administration, and remediation. We do not support unauthorized access, credential theft, evasion, destructive or disruptive activity, harmful exploitation, or surveillance without authorization.
Advanced-model access
Any privileged or advanced model access granted to Apogee1 is used internally by authorized Apogee1 personnel for approved defensive work. It is not resold, proxied, embedded in a public product, exposed through customer traffic, or made available to third parties.
Data, access, and review
We minimize the data, secrets, and privileges used in research; prefer test or synthetic data where practical; and keep a human responsible for scope, review, and consequential actions. Products are designed to make evidence and operator intent visible rather than obscure them.
Responsible disclosure
If our work reveals a vulnerability affecting another party, we seek the appropriate security contact, provide enough reproducible evidence to support remediation, avoid unnecessary exposure of sensitive details, and coordinate disclosure where practical. Our Security Disclosure Policy explains how to report a suspected vulnerability affecting Apogee1, and our Privacy Policy explains how we handle personal information.
Report a security concern
For a vulnerability, suspected misuse, or other security concern involving Apogee1, email contact@apogee1.net. Please do not include credentials, secrets, or sensitive personal data in an initial email. Our machine-readable contact information is available in security.txt.