Short version: Report security issues in good faith to security@breaklinesecurity.com. Give us reasonable time (90 days, dependent on severity) to fix them before going public. Don't break, exfiltrate, or degrade anything.

Scope

This policy covers assets operated by BREAKLINE SECURITY, including:

  • This website (breaklinesecurity.com and its subdomains)
  • The BREAKLINE platforms and tooling we distribute, where the issue affects the shipped product itself

Because our platforms are self-hosted, we do not operate our customers' deployments. Issues you find in your own installation are in scope as product defects; the running infrastructure it sits on is not ours to test.

How to report

Email security@breaklinesecurity.com. A machine-readable pointer to this policy lives at /.well-known/security.txt. To help us reproduce and triage quickly, please include:

  • A clear description of the issue and its potential impact
  • Step-by-step instructions to reproduce it
  • The affected URL, endpoint, product, or version
  • Any proof-of-concept, logs, or screenshots (please redact real user data)

If you'd like to encrypt your report, say so and we'll arrange a key exchange.

What we ask of you

  • Act in good faith and avoid privacy violations, data destruction, and service disruption
  • Only interact with instances and accounts you own or have explicit permission to test
  • Stop and report as soon as you've established that a vulnerability exists
  • Do not access, modify, or exfiltrate data that isn't yours; if you encounter someone else's data, stop and tell us
  • Give us a reasonable period to remediate before any public disclosure

What you can expect from us

  • An acknowledgement of your report, typically within 5 business days
  • An honest assessment of the issue and, where valid, a plan and timeline to fix it
  • Updates as we work through remediation
  • Credit for your findingd

Safe harbour

We will not pursue legal action against researchers who discover and report vulnerabilities in accordance with this policy. We'll work with you to understand and resolve the issue quickly.

This safe harbour does not extend to actions that go beyond good-faith research — for example, accessing or destroying data, degrading service, or violating the privacy of others.

Rewards

We do not currently run a paid bug bounty. We're a young company, and we'd rather be honest than dangle a payout we can't stand behind. What we can promise is a genuine thank-you and public credit if you want it.

Once we're properly established, we intend to offer BREAKLINE swag as a token of thanks for valid, good-faith reports. Any such reward is at our discretion.

Out of scope

The following are generally not eligible under this policy unless you can demonstrate a concrete, exploitable impact:

  • Reports from automated scanners without a working proof-of-concept
  • Missing security headers or best-practice suggestions with no demonstrated exploit
  • Denial-of-service, volumetric, or brute-force testing
  • Social engineering, phishing, or physical attacks against our staff or offices
  • Issues in third-party services we do not control, or in customers' self-hosted infrastructure
Last updated: September 2026  ·  security@breaklinesecurity.com