1. Comprehensive Legal Safe Harbor
If you conduct vulnerability research and disclose security issues in accordance with this policy, BuruOps considers your actions to be authorized under Section 1(1) of the UK Computer Misuse Act 1990. We will not pursue civil litigation against you, nor will we refer you to UK police or statutory authorities for prosecution.
If a third party initiates legal action against you regarding activities conducted in strict adherence to this policy, BuruOps will publicly confirm that your activities were conducted with our explicit authorization.
2. Scope of Systems
In-Scope Systems
https://buruops.comand direct subdomains- BuruOps production web application runtime
- Publicly reachable API endpoints and routing scripts
- BuruOps open-source repositories on GitHub (
github.com/BuruOPS)
Out-of-Scope Activities
- Volumetric Denial of Service (DoS/DDoS) attacks
- Physical security testing of offices or data centers
- Social engineering, phishing, or vishing of staff
- Third-party SaaS providers (e.g., Cloudflare, GitHub) outside our direct tenant configs
3. Rules of Engagement for Researchers
To remain eligible for Safe Harbor protection, you must adhere strictly to these principles:
- No Data Exfiltration: If you discover a vulnerability that exposes sensitive or personal data, view only the minimum amount required to demonstrate a Proof-of-Concept (PoC). Do not copy, download, retain, or disclose client data.
- No Service Disruption: Do not execute payloads that modify server configurations, alter database records, or impair service availability for other users.
- 90-Day Coordinated Disclosure Window: Provide us with at least 90 calendar days from report acknowledgment to triage, develop, test, and deploy a remediation before any public disclosure or conference presentation.
- Maintain Confidentiality: Do not disclose vulnerability details to any third party without our prior written consent.
4. How to Submit a Vulnerability Report
Please email all vulnerability reports directly to principal@buruops.com. Include:
- Clear summary of the vulnerability class (e.g., SSRF, Auth Bypass, IDOR, SQLi).
- Step-by-step reproduction instructions and minimal HTTP request transcripts.
- Estimated severity rating (CVSS v3.1 vector if known).
BuruOps Security PGP Public Key
Comment: BuruOps Intelligence Lab Security Triage Key (RSA 4096)
mQINBGB8aNkBEADNxm2+Y57BkJb5gH... (BuruOps Master PGP Key)
Fingerprint: 8F2A 3E4B 91C0 4D8E 7F6A 2B1C 9D8E 0F1A 3B4C 5D6E
Uid: BuruOps Security Triage <principal@buruops.com>
-----END PGP PUBLIC KEY BLOCK-----
5. Acknowledgments & Hall of Fame
BuruOps maintains a Security Researcher Hall of Fame acknowledging researchers who have responsibly reported valid vulnerabilities in accordance with this policy. While we do not operate a commercial bug bounty program, qualifying reports are formally recognized with institutional citation, custom recommendation letters, and commemorative cryptographic tokens.