Request assessment
Start with the application context, not the credentials.
Give us enough information to understand the product and assessment goal. Sensitive access material comes only after the engagement has been scoped through an appropriate channel.
01
This request does not authorize testing.
02
We review fit and define the intended scope.
03
Rules of Engagement and written authorization come before testing.
Public intake only
Do not include passwords, API keys, session tokens, customer data, source archives, exploit payloads, or confidential access details.