Skip to main content
BuruOps Defensive Security Research and Vulnerability Disclosure
DEFENSIVE RESEARCH • ISO/IEC 29147 • RFC 9116

Vulnerability Disclosure Policy

BuruOps Intelligence Lab welcomes responsible, coordinated disclosure of security vulnerabilities from ethical researchers, academic cryptographers, and defensive engineers. We provide an unambiguous Safe Harbor protecting good-faith security researchers from legal exposure under the UK Computer Misuse Act 1990.

Read Safe Harbor Terms Download PGP Key RFC 9116 security.txt
SAFE HARBOR
Active Guarantee
CMA 1990 Immunity
DISCLOSURE STANDARD
ISO/IEC 29147
Coordinated 90-Day Window
TRIAGE SLA
< 48 Hours
Principal Triage
ENCRYPTION
RSA 4096 / PGP
Encrypted Submission

1. Comprehensive Legal Safe Harbor

If you conduct vulnerability research and disclose security issues in accordance with this policy, BuruOps considers your actions to be authorized under Section 1(1) of the UK Computer Misuse Act 1990. We will not pursue civil litigation against you, nor will we refer you to UK police or statutory authorities for prosecution.

If a third party initiates legal action against you regarding activities conducted in strict adherence to this policy, BuruOps will publicly confirm that your activities were conducted with our explicit authorization.

2. Scope of Systems

In-Scope Systems

  • https://buruops.com and direct subdomains
  • BuruOps production web application runtime
  • Publicly reachable API endpoints and routing scripts
  • BuruOps open-source repositories on GitHub (github.com/BuruOPS)

Out-of-Scope Activities

  • Volumetric Denial of Service (DoS/DDoS) attacks
  • Physical security testing of offices or data centers
  • Social engineering, phishing, or vishing of staff
  • Third-party SaaS providers (e.g., Cloudflare, GitHub) outside our direct tenant configs

3. Rules of Engagement for Researchers

To remain eligible for Safe Harbor protection, you must adhere strictly to these principles:

  • No Data Exfiltration: If you discover a vulnerability that exposes sensitive or personal data, view only the minimum amount required to demonstrate a Proof-of-Concept (PoC). Do not copy, download, retain, or disclose client data.
  • No Service Disruption: Do not execute payloads that modify server configurations, alter database records, or impair service availability for other users.
  • 90-Day Coordinated Disclosure Window: Provide us with at least 90 calendar days from report acknowledgment to triage, develop, test, and deploy a remediation before any public disclosure or conference presentation.
  • Maintain Confidentiality: Do not disclose vulnerability details to any third party without our prior written consent.

4. How to Submit a Vulnerability Report

Please email all vulnerability reports directly to principal@buruops.com. Include:

  • Clear summary of the vulnerability class (e.g., SSRF, Auth Bypass, IDOR, SQLi).
  • Step-by-step reproduction instructions and minimal HTTP request transcripts.
  • Estimated severity rating (CVSS v3.1 vector if known).

BuruOps Security PGP Public Key

-----BEGIN PGP PUBLIC KEY BLOCK-----
Comment: BuruOps Intelligence Lab Security Triage Key (RSA 4096)

mQINBGB8aNkBEADNxm2+Y57BkJb5gH... (BuruOps Master PGP Key)
Fingerprint: 8F2A 3E4B 91C0 4D8E 7F6A 2B1C 9D8E 0F1A 3B4C 5D6E
Uid: BuruOps Security Triage <principal@buruops.com>
-----END PGP PUBLIC KEY BLOCK-----

5. Acknowledgments & Hall of Fame

BuruOps maintains a Security Researcher Hall of Fame acknowledging researchers who have responsibly reported valid vulnerabilities in accordance with this policy. While we do not operate a commercial bug bounty program, qualifying reports are formally recognized with institutional citation, custom recommendation letters, and commemorative cryptographic tokens.