Skip to content
O
boringsec/legal/security outreach policy

Security Outreach Policy

How BoringSec limits evidence-based business security notices, automated approval, delivery, and opt-out handling.

effective August 26, 20267 sectionsRead Privacy Policy
01

Purpose and Scope

in plain english

We may send a limited business security notice when fresh public evidence shows a material issue and the recipient can verify it independently.

02

Evidence Boundary

in plain english

An automated message needs a recent passive assessment, enough coverage, a material signal, and a safe explanation of its limits.

03

Recipient and Jurisdiction Boundary

in plain english

We use attributable public business or security contacts, never bought or guessed personal addresses, and fail closed when jurisdiction is unclear.

04

Message and Cadence

in plain english

The first note is evidence-first, follow-ups are capped, and any reply or opt-out stops automation immediately.

05

Delivery, Audit, and Emergency Stop

in plain english

Every attempt is rate-limited, deduplicated, recorded, and governed by an immediate operator kill switch.

06

Privacy and Contact Choice

in plain english

We keep only the minimum contact and delivery evidence needed for the bounded sequence, and every message provides an easy opt-out.

07

Policy Identity and Review

in plain english

This is boringsec-us-commercial-outreach/v2. Material changes require a new version and production configuration review.