If you have found a security issue in anything we run, we want to hear about it. This page is the process.
Write to security@sirenbow.com. Include enough detail for us to reproduce the issue: affected URL or component, steps, and impact. Machine-readable contact details are at /.well-known/security.txt.
If you make a good-faith effort to follow this policy — no data destruction, no service disruption, no access beyond what is needed to demonstrate the issue — we will not pursue legal action against you for the research itself.
Denial-of-service testing, social engineering of our staff or clients, and physical testing are not covered by this policy. Reports about third-party systems should go to those vendors, not to us.
When we find issues in third-party systems during authorized work, we coordinate privately with the vendor first and publish only after a fix or an agreed deadline. Our published post-mortems cover incidents that are already public.