Code of Conduct

Code of Conduct and Responsible Disclosure

Updated: 2026-06-06

NEOSEC Intel is a situational-awareness platform for vulnerability and threat intelligence. As a security vendor we take seriously the responsibility that comes with running a public-facing security service. This Code of Conduct describes how we engage with good-faith security research against our platform — and what we expect from researchers and users in return.

Spirit and intent

We believe good security work is built on mutual trust, transparent communication and the willingness to admit and fix mistakes quickly. A researcher who finds a flaw in NEOSEC Intel helps us — and, indirectly, every user of our platform. That help deserves a serious, timely and respectful response from us.

Scope

This Code of Conduct covers the production platform intel.neosec.io and all related subdomains and APIs. The public NEOSEC corporate website and other NEOSEC platforms are out of scope. For those, as well as for any third-party services we rely on, please contact the respective operator separately.

Safe harbor for good-faith research

Researchers who conduct security testing against intel.neosec.io in good faith and within the bounds of this Code of Conduct have our commitment that we will not pursue civil or criminal action and will not file a complaint under §§ 202a–202c StGB or § 303a StGB. This commitment extends to any activity that stays within the boundaries described under "Allowed research". If a third party brings legal action against you and you have complied with this Code of Conduct, we will publicly confirm the research intent and, where appropriate, act as a witness.

Allowed research

Only against intel.neosec.io and only using your own test accounts and data: • Testing against your own accounts and sessions • Observing API responses and header behavior • Static analysis of the publicly served frontend • Probing documented and undocumented endpoints • Analysis of the publicly available API responses • A single, well-documented proof-of-concept request per suspected vulnerability

Prohibited actions

• Denial-of-service or load testing that impacts other users • Mass scraping beyond the applicable rate limits • Accessing other users' data, including subscriber or customer personal data • Persistence: leaving backdoors, web shells or modified records • Pivoting into non-public, internal NEOSEC systems of any kind • Social engineering of NEOSEC staff, customers or subscribers • Public disclosure of the vulnerability before the agreed disclosure deadline

Reporting a vulnerability

Please report vulnerabilities exclusively via encrypted email to intel@neosec.eu. Our PGP key is available at https://intel.neosec.io/.well-known/pgp-key.txt. A report should include: • A clear description of the vulnerability and a severity assessment (CVSS v3.1 or v4.0) • Reproduction steps or a proof-of-concept • Affected endpoints / URLs / functions • Suspected impact • Your preferred name for a possible Hall of Fame mention (or your wish to remain anonymous) If during testing you inadvertently encounter personal data of third parties, stop access immediately, do not store or share that data and inform us in your report.

Response SLAs

• Acknowledgment of receipt: within 2 business days • First triage with severity rating: within 5 business days • Patch or mitigation plan: within 14 days for High/Critical, 30 days for Medium, 90 days for Low • Status updates: at least every 14 days until resolution If a vulnerability is already public or actively exploited, we accelerate our response accordingly.

Coordinated disclosure

We prefer coordinated disclosure after the fix has shipped. You may publish about the vulnerability after 90 days from initial report — or sooner if we agree mutually. We reserve the right to publish our own writeup (blog post, changelog entry, or CVE filing) in parallel or beforehand. If you would like a CVE ID for your finding, we will request one from MITRE.

Recognition

NEOSEC Intel is a free public-service offering by NEOSEC GmbH during public beta. We do not operate a monetary bug bounty. With your consent we will list you in our Hall of Fame at /code-of-conduct/hall-of-fame with your name or handle, the bug category and the date. A bug bounty program for the customer-tier XIEM platform is being evaluated for a later stage.

Out of scope

The following findings are generally not accepted as security vulnerabilities: • Missing HTTP security headers without demonstrable impact • Theoretical self-XSS without an attack vector • Best-practice deviations without an exploitation path • Login brute-force without account-lockout bypass • CSRF on non-sensitive endpoints without protection requirement • Clickjacking on pages without security-relevant actions • Version or banner information of deployed software without a demonstrated, practically exploitable vulnerability • Reports from automated scanners (e.g. Burp Suite, OWASP ZAP, Nuclei) without manual validation

Violations

Anyone who violates this Code of Conduct — in particular the items listed under "Prohibited actions" — loses the protection of the safe-harbor clause. We reserve the right to pursue civil and criminal action and to apply technical countermeasures, including the permanent blocking of source IPs. Please report violations to intel@neosec.eu as well.

NEOSEC Intel — NEOSEC Intel