Legal
Responsible Disclosure Policy
Last updated: January 1, 2026
We hold our own infrastructure to the same rigor we test our clients against, and welcome good-faith security research.
Our Commitment
As a security firm, we hold our own systems to the same standard we test our clients against. We welcome reports from independent researchers who identify vulnerabilities in RedShield Defense's own infrastructure.
Scope
This policy covers redshielddefense.com and RedShield Defense-operated infrastructure. It does not cover the systems of our clients, which are governed by their own disclosure policies.
Reporting Guidelines
Please report suspected vulnerabilities to security@redshielddefense.com with sufficient detail to reproduce the issue. Do not access, modify, or exfiltrate data beyond what is necessary to demonstrate the vulnerability.
- Provide a clear description and steps to reproduce
- Avoid automated scanning that could degrade service availability
- Give us reasonable time to remediate before public disclosure
Our Response
We acknowledge reports within two business days and aim to provide a remediation timeline within ten business days of confirming a valid finding.
Safe Harbor
We will not pursue legal action against researchers who make a good-faith effort to comply with this policy while identifying and reporting a vulnerability.
