What is in scope
This policy covers the systems Eigenvector IT operates in its own name. The list below names them, and it is kept current.
- The website eigenvector.group and its subdomains.
- The firm's public mail infrastructure, including the records that govern who may send in its name.
- File transfer and collaboration services the firm operates for its own engagements.
- Software, packages and configuration the firm publishes under its own name.
If you are unsure whether something belongs to the firm, send the report anyway and say what led you to it. Deciding scope is our job, not yours.
What is out of scope
Client systems are out of scope in every case. The firm cannot authorise testing of an estate it does not own, and no engagement gives it that authority. If you believe you have found a vulnerability in a client's system, stop testing, write to enquiries@eigenvector.group with what you already hold, and we will route it to the client through the contact named in that client's contract.
- Systems operated by third parties, including hosted services the firm buys.
- The homes, personal devices and personal accounts of the people who work here. Anything aimed at a person rather than at the firm's systems is not treated as research, and the safe harbour below does not reach it.
- Social engineering of the people who work here, of clients or of suppliers, including unsolicited phishing tests.
- Denial of service, load testing and any technique whose effect is volume.
- Sustained automated scanning, and scanner output submitted with no demonstrated impact.
- Findings that depend on an unsupported browser, a rooted device, or a user acting against their own interest.
- Missing headers, cookie flags, version disclosure and similar configuration observations with no path to impact.
Out of scope does not mean unwelcome as information. It means we will read it, thank you for it, and not treat it as a vulnerability report.
Safe harbour
The firm takes no action against good-faith research. Where you follow this policy, we will not bring a civil claim, will not refer you to law enforcement, and will not approach your employer, your university or your registrar. If a third party acts against you over research that stayed inside this policy, we will state in writing that the work was authorised.
Good faith means all of the following.
- You stayed inside the scope set out above.
- You stopped at proof. Access enough to demonstrate the finding, and no further.
- You did not read, copy, alter, retain or publish anyone's data. If personal data was exposed to you, you stopped, told us at once, and deleted what you held after we confirmed receipt.
- You did not degrade a service, destroy data or lock anyone out.
- You gave us the time set out under coordinated disclosure before publishing.
- You attached no payment demand to the report. A finding withheld pending payment is extortion, and it is handled as extortion.
This protection is given by the firm and binds the firm. It cannot bind a provider whose platform sits underneath ours, which is one more reason to keep the testing on the systems listed above.
How to report
Reports go to enquiries@eigenvector.group. That is the only address the firm publishes, and a researcher, a client and a supplier all use it.
There is no separate security mailbox and no incident alias. Mail sent to an address of that kind reaches nobody here, because no such mailbox exists. There is no form, no portal and no bounty platform in front of this policy either.
The machine-readable copy of this policy, carrying the same address in its contact field, is published at https://eigenvector.group/.well-known/security.txt.
A report we can act on carries:
- The host, address or endpoint affected, with the date and time you tested it.
- What the vulnerability is, in a sentence a defender can act on.
- Steps to reproduce it, in order, including any account or precondition required.
- Evidence: a request and response, a screenshot, or a short recording.
- What an attacker could do with it, in your assessment.
- The tools you used, and anything you changed on the system.
- How you want to be credited, or that you would rather not be.
Write in English. Put the word Vulnerability first in the subject line so that it is triaged as one.
Encryption
The firm publishes no PGP key. When a key exists it is published in the encryption field of https://eigenvector.group/.well-known/security.txt, with its fingerprint printed alongside, and this page is updated on the same day. Until that happens, treat the address as an unencrypted one.
So send the report in plain text and keep exposed data out of it. Describe what you saw rather than attaching it. Where a finding cannot be explained without sensitive material, say so in the first message and we will agree a channel for that material within one working day.
What happens after you report
- Receipt is acknowledged within one working day, by a person, with a reference number.
- Within 5 working days we tell you whether we reproduced the finding and how we rated it.
- A written update follows at least every 10 working days until the report is closed.
- When the fix ships, we tell you what changed and invite you to retest it.
Triage is done by the firm's own people: the engineer who owns the affected system, working with Priyanka Raghunathan, Practice Lead, Cyber Defence. No part of this process is outsourced, and no report is closed without a written outcome.
Reports are read on working days. The firm publishes no route that is faster than the one on this page, because it does not have one. The acknowledgement is a commitment in writing, and it holds.
Coordinated disclosure
You are free to publish. We ask that you wait 90 days from the day we acknowledge the report, so that a fix is in place before the method is public.
There are two adjustments to that, both agreed in writing. If the fix ships early and you want to publish early, say so and we will normally agree. If remediation proves harder than it first looked, we will ask you for a specific extension, give the reason, and give a date. We will not ask twice for the same finding, and we will not use an extension to postpone publication indefinitely.
Where we publish the fix, or write a field note about it, we credit you by the name you give us. If you would rather not be named, you will not be.
The firm runs no paid bounty
There is no bounty programme, no payment scale, and no negotiation over one. Reports are not bought. What a report earns is an acknowledgement within one working day, triage by named people, a written outcome, credit where you want it, and a fix you can verify yourself.
This is stated plainly so that nobody spends a weekend on these systems expecting a payment that is not coming.