Report it to us directly.
If you have found a security vulnerability in a system BrandShyp operates, we want to hear from you. Email [email protected] with “Security” in the subject line. You may report anonymously.
We are a small firm and we do not run a 24/7 security desk. The response times below are what we can actually meet, not what sounds impressive.
Our security & compliance posture
Stated plainly, including what is done and what is still in progress. We do not claim credentials we have not earned.
CMMC Level 2 & NIST 800-171
Our NIST SP 800-171 self-assessment is complete and affirmed in SPRS as CMMC Level 2 (Self-Assessment), backed by a CUI enclave using FIPS-validated cryptography. A readiness posture, not a C3PAO certification.
SOC 2 (Security Criteria)
We hold our own systems to the SOC 2 Security Trust Services Criteria and run the same assessment we publish as a free tool. Readiness is in progress; no third-party attestation has been engaged yet. We reuse our NIST 800-171 overlap and track every gap in a POA&M.
Use the free tool →Ongoing practice
This vulnerability disclosure policy, dependency vulnerability scanning with SBOM generation on our own code, enforced MFA, endpoint hardening, and encrypted nightly backups.
Our response
Deliberately conservative targets that we can meet.
Acknowledgement
We confirm we received your report within three business days.
Triage
An initial assessment and severity rating within ten business days.
Updates
A status update every thirty days while work continues, and a notification when it is resolved.
What is and is not covered
In scope
- brandshyp.org and its subdomains
- The free tools and public APIs hosted there
- Client websites BrandShyp hosts or maintains, to the extent we control them
Out of scope
- Third-party services we merely use (report those to the provider)
- Findings requiring physical access, social engineering of our staff, or a compromised end-user device
- Volumetric denial-of-service testing
- Automated scanner output with no demonstrated, exploitable impact
Research in good faith is welcome
In return, we ask that you:
- Avoid privacy violations, data destruction, and service degradation
- Access only the minimum data needed to demonstrate the issue, and never save, transfer, or use third-party data you encounter
- Give us reasonable time to remediate before disclosing publicly
BrandShyp does not currently offer monetary bounties. We will credit researchers who wish to be named once an issue is resolved.
Machine-readable version: /.well-known/security.txt (RFC 9116).