TBOC2, LLC welcomes responsible, good-faith vulnerability reporting for systems expressly identified as in scope.
Reporting
Send reports to security@tboc2.com. Machine-readable contact information is at /.well-known/security.txt.
Include
Provide the affected URL or component, reproduction steps, observed and expected behavior, potential impact, and relevant proof-of-concept material. Do not include unnecessary personal, customer, or confidential information.
Good-faith expectations
Minimize privacy impact and disruption; stop if sensitive or unauthorized data is encountered; avoid persistence and destructive actions; and allow reasonable time for investigation before disclosure.
Not authorized
This policy does not authorize denial-of-service testing, social engineering, phishing, physical or credential attacks, spam, malware, destructive testing, excessive data access, testing customer-controlled deployments without explicit authorization, or testing third-party systems merely because they interact with TBOC2.
Customer deployments
Customer environments are customer-controlled systems. This policy does not grant permission to test them. Authorization must come from the applicable system owner.
Safe-harbor intent
For research conducted in good faith within this policy and intended to avoid harm, TBOC2 intends to work constructively with the reporter. This statement is not a waiver of rights, does not bind third parties, and is subject to attorney review.
Bounties
TBOC2 does not currently promise a bounty, payment, or public recognition unless expressly agreed in writing.