Contact

Tell us what is authorized—and what must remain untouched.

A useful first message identifies the system owner, the question and the expected testing boundary. Do not send secrets.

01

Good first fit

AI agents, MCP servers, authorization-sensitive applications, open-source components and existing vulnerability claims.

02

What happens next

We review fit and authorization before requesting files, credentials or any access to a target.

Do not include credentials, secrets, customer data or exploit payloads.