RESPONSIBLE DISCLOSURE

Security

Clear reporting, bounded scope, and no manufactured promises.

Reporting

Downum Cyber does not yet operate a dedicated security-reporting mailbox. For an initial responsible-disclosure contact, email Scott at scott@downumcyber.com. This is a verified professional business address, not a dedicated security alias.

Do not include exploit details, credentials, secrets, or other sensitive material in the first message. Begin with a concise summary and coordinate a suitable exchange method before sending technical evidence.

Authorization and scope

No testing is authorized without prior written permission. Private RAGNAROK infrastructure, personal systems, third-party providers, and denial-of-service testing are not public targets.

No bounty promise

Downum Cyber does not currently operate a vulnerability bounty program. Good-faith reporting guidance will be expanded as the public surface grows.

Public media boundary

Portfolio media is reviewed before publication and never creates a live connection to a private command center, model endpoint, database, event stream, or administrative surface.