Coordinated Disclosure

Security Disclosure Policy

Effective Date: May 9, 2026

Report a Vulnerability

security@shadowspan.com

Acknowledgement within 2 business days. PGP key available on request.

Shadow Span Technologies Inc. welcomes reports of security vulnerabilities in the Shadow Span platform. We commit to working with security researchers in good faith to verify, reproduce, and remediate reported issues. This policy explains what we expect from researchers and what they can expect from us.

How to Report

Send vulnerability reports to security@shadowspan.com. Encrypt sensitive details if you wish — PGP key available on request.

A useful report includes: a clear description of the issue, affected URL or endpoint, reproduction steps, proof-of-concept (curl command, request/response, or short video), the impact you believe an attacker could achieve, and your name or handle if you would like to be credited.

Please do not file public GitHub issues, social-media posts, or support tickets for security matters before we have had a chance to respond.

Our Commitments to Researchers

Acknowledgement of receipt within 2 business days.

Initial triage and severity classification within 5 business days.

Status updates at least every 14 days while the issue is open.

Public credit in our security acknowledgements page once the issue is resolved, if you wish.

We will not pursue legal action against researchers who follow this policy in good faith. See "Safe Harbor" below.

Target Response Times by Severity

Critical (RCE, authentication bypass, cross-tenant data exposure): mitigation within 72 hours, fix within 7 days.

High (privilege escalation within a tenant, sensitive PII leak, SSRF): fix within 14 days.

Medium (XSS, CSRF, IDOR with limited blast radius): fix within 30 days.

Low (information disclosure with minimal impact, security-header omissions): fix within 90 days.

These are targets, not guarantees. We will update you if a fix needs longer.

In Scope

app.shadowspan.com — the production Shadow Span web application and its API surface.

shadowspan.com — the marketing site and public landing pages.

Mobile clients and command-line tools distributed by Shadow Span Technologies Inc..

Our public REST API, TAXII server, and STIX export endpoints.

Out of Scope

Findings against third-party infrastructure we depend on (Cloudflare, Supabase, Google Cloud, Resend, Upstash). Report those directly to the vendor.

Denial-of-service, volumetric attacks, or anything that intentionally degrades service for other customers.

Social engineering against our staff, customers, or vendors.

Physical attacks against our offices or data centres.

Reports generated solely by automated scanners (Nessus, Burp, Acunetix, etc.) without manual validation of impact.

Missing security headers, cookie attribute issues, or TLS/cipher misconfigurations on pages that do not handle authenticated traffic.

Clickjacking on pages without authenticated state-changing actions.

Self-XSS, tab-nabbing, or attacks requiring physical access to an unlocked device.

Findings against staging, development, or `*.run.app` Cloud Run direct URLs — these are not production surfaces.

Safe Harbor

We consider security research conducted under this policy to be authorised conduct. We will not pursue legal action against researchers who, in good faith:

1. Make a sincere effort to avoid privacy violations, destruction of data, and interruption or degradation of our Service.

2. Only interact with accounts you own or with explicit permission of the account holder.

3. Do not access, modify, or exfiltrate data beyond the minimum necessary to demonstrate the vulnerability.

4. Report the issue to us promptly and give us reasonable time to respond before any public disclosure.

5. Comply with all applicable laws in their jurisdiction.

If you are unsure whether a particular research activity is permitted, contact us before you begin. We would rather answer a question than have to interpret intent after the fact.

Rewards

Shadow Span does not currently operate a paid bug bounty programme. We are an early-stage company, and our reward today is public credit (with your consent) on our acknowledgements page and a written thank-you. We will revisit a paid programme as the company grows.

If you discover a critical issue and would prefer not to be publicly credited, just let us know.

Public Disclosure

We ask that you give us reasonable time to remediate before publishing details. "Reasonable" usually means 90 days from the date of our acknowledgement, or earlier if we agree.

For critical issues that are being actively exploited in the wild, we may agree to a shorter disclosure window. For complex issues requiring coordination with downstream consumers, we may ask for an extension.

We will work with you on a coordinated disclosure timeline and are happy to publish a joint advisory if you wish.

Questions

If you have questions about this policy or about whether a planned research activity is permitted, email security@shadowspan.com before you begin.

Shadow Span Technologies Inc.