Skip to content
Red Cell

Responsible disclosure

Responsible disclosure.

Red Cell finds security exposure and tells the people who own it. This page states exactly how we work, so there is no ambiguity about what we do, what we don’t, and what you can expect if we contact you — or if you contact us.

Two kinds of work, one hard line between them

Public-source assessment. We can learn a great deal about an organization’s exposure from information and artifacts that are already public — published web applications, distributed client software and browser extensions, certificate records, and other openly available material. This work touches nothing we are not free to access. We do not log into your systems, we do not test your infrastructure, and we do not exercise any credential we find.

Authorized testing. Anything that sends a request into a client’s systems — validating a finding, testing an application, exploiting a weakness — begins only after a signed scope agreement and written rules of engagement. No packet touches a client system without that agreement in place. There are no exceptions, because that line is the difference between security work and intrusion.

How we handle a finding

  • We disclose privately. Findings go to the affected organization, not to the public, the press, or anyone else. We do not publish or sell them.
  • We give you enough to verify it yourself. Where a finding involves a secret, we reference it by fingerprint or hash, never by its raw value, and we describe checks you can run on your own infrastructure. You confirm severity; we don’t have to touch your systems for you to believe us.
  • We describe, we don’t weaponize. Findings are written at a level that lets you fix them — category, impact, remediation. We do not include exploit code or step-by-step attack instructions in a disclosure.
  • We never withhold a security finding as leverage. A remediation path comes with the finding, whether or not you ever engage us. We do not hold a fix hostage to a contract, and we do not use what we find to pressure anyone.

If you’ve received a disclosure from us

It means we found something from public sources and thought you should know before someone less friendly did. Everything we found, an acquirer’s diligence team or a hostile researcher can find the same way. Read it, verify it on your own infrastructure using the steps we provide, and act on it — engaging us is optional and separate.

If you want to report something to us

If you believe you’ve found a vulnerability in a Red Cell property, or in a system we operate, tell us through the contact page. We’ll acknowledge it, work it in good faith, and we won’t pursue anyone acting in good faith under this policy.

This page describes how Red Cell operates. It is not legal advice.