Vulnerability disclosure
If you have found a security problem in Shrike, we want to hear about it, and we will not take action against good-faith research that follows this page.
How to report
Email security@shrikesecurity.com. Include what you found, where, and the steps to reproduce it. A proof of concept helps; customer data does not, so please do not include any. This address is also published in our security.txt.
What we commit to
- An acknowledgement within two business days.
- An assessment and a first response on severity within seven days.
- A fix or a mitigation plan for confirmed issues, with a timeline shared with you.
- Credit on request once the issue is resolved, or anonymity if you prefer.
In scope
- The platform at shrikesecurity.com and its APIs, including the scan and dashboard endpoints.
- The published clients: the MCP server and the Python, TypeScript and Go SDKs.
- Detection bypasses that let a governed action through a control that should have held it.
Out of scope
- Denial of service, volumetric testing, or anything that degrades service for others.
- Social engineering of our staff or customers.
- Access to, or exfiltration of, any data that is not your own. Stop and report the moment you can see another tenant's data.
- Reports from automated scanners with no demonstrated impact.
Safe harbour
Research that stays within this page, avoids privacy violations and service disruption, and gives us reasonable time to fix an issue before any public disclosure is authorised, and we will not pursue legal action for it. If you are unsure whether something is covered, ask first.
Related: Privacy Policy, Terms of Service, Compliance.