SECURITY / COORDINATED DISCLOSURE
Help us protect the network.
If you find a vulnerability in Layer400, report it privately and give us a reasonable opportunity to investigate. This page explains how to do that without increasing the risk to users or receiver operators.
1. Reporting a vulnerability
Email [email protected] with a concise description, affected URL or component, reproducible steps, observed impact and any non-sensitive evidence. Include an address we can use for follow-up and say whether disclosure is time-sensitive.
Use a minimal proof. Redact personal data, credentials, precise receiver locations and private telemetry. If the report needs a safer transfer method, ask for one before sending sensitive material.
2. Good-faith research
We welcome testing that is lawful, uses your own account or equipment, avoids harm, stops once impact is demonstrated and follows this policy. Where a researcher acts in good faith and within these boundaries, our intention is to work constructively to resolve the issue rather than threaten action. This statement cannot authorise conduct against a third party or override applicable law.
3. Testing that is not authorised
- denial-of-service, load or volumetric testing;
- social engineering, phishing, impersonation or attacks on staff, contributors or support providers;
- physical access, interference with receivers, radio jamming or transmitting false Remote ID;
- malware, persistence, destructive changes or modification of another person’s data;
- automated scanning that creates material traffic or bypasses a stated limit;
- accessing more personal, account or restricted observation data than is needed to prove the issue; or
- testing services owned by a third party without that provider’s permission.
If you encounter another person’s data or gain unintended privileged access, stop, do not retain or share the data, and report the issue.
4. What we will do
We will triage credible reports, investigate proportionately, preserve relevant records and work towards a fix based on severity and operational risk. We aim to acknowledge useful reports promptly, but do not promise a fixed response or remediation time.
We may ask you to verify a fix or delay public disclosure while users and receivers are protected. We will not ask you to keep an issue secret indefinitely. Please coordinate a publication date rather than exposing an unpatched weakness without warning.
5. Recognition and rewards
Layer400 does not currently promise a bug bounty or payment. We may offer public credit, with permission, for a helpful report. Recognition is not available for reports based only on automated output, missing best-practice headers without a demonstrated impact, self-XSS or issues already known to us.
6. Other concerns
Use Corrections and reports for an incorrect track, privacy concern or suspected data manipulation that does not expose a technical vulnerability. Use the account support route for ordinary sign-in or receiver setup help.