Coordinated disclosure
Telling us something is broken
Published terms, a named destination, and a commitment not to pursue anyone acting in good faith. If you have found a problem, we would rather hear it from you.
How to report
Write to [email protected]. Include what you found, how to reproduce it, and what you think the impact is. A rough description is fine; we would rather have a vague report than none.
A machine-readable version of this page is published at
/.well-known/security.txt.
Our commitments
- Acknowledgement within 3 working days. From a person, not an autoresponder.
- An assessment within 14 days, including our view of severity and whether we intend to fix it.
- Disclosure at 90 days by default, or sooner by mutual agreement. If we need longer we will say why, and you are under no obligation to agree.
- Credit if you want it, and none if you do not.
- We will not sell your finding to anyone, and we do not buy findings from anyone.
Safe harbour
We will not pursue legal action, or ask anyone else to, against a researcher who acts in good faith under these terms: who avoids privacy violations and service degradation, who does not access or modify data beyond what is needed to demonstrate the issue, and who gives us a reasonable opportunity to respond before publishing.
If you are unsure whether something is in scope, ask first. An enquiry is never itself a violation.
Scope
In scope:
sentinelco.caandwww.sentinelco.ca
Out of scope:
- Any host not named above. Systems outside the two hostnames listed are not part of this site and are not covered by this policy or its safe harbour.
- Findings that amount to a missing hardening header on a static site with no authentication, no cookies and no user input. We have set them anyway; reports that consist only of a scanner's output are unlikely to be actioned.
- Social engineering, physical access, and denial of service.
What this site actually is
Worth stating plainly for anyone assessing risk: this is a static site. It has no database, no server-side application, no authentication, no session state and no user input of any kind. Every page is a file rendered ahead of time and served by a web server. The realistic vulnerability surface is small, and that is by design rather than by luck.
The terms on this page govern reports about this website and the infrastructure serving it. Our wider disclosure work is described under Initiatives. A report sent to the address above will be read and answered by a person.