We hold ourselves to the standard we sell.
How threatDefendr secures its own platform, and how researchers can report a vulnerability — with a clear policy, safe harbor, and a bounty for the people who help keep us honest.
Security is the product — and the posture.
TLS 1.3 in transit, AES-256 at rest, and customer-managed keys for tenant data.
Threat modeling, SAST/DAST/SCA in CI, and signed, provenance-tracked artifacts.
Independent annual pen tests, an internal red team, and an always-on bug bounty.
Zero-trust internal access, hardware MFA, and just-in-time grants on production.
Report in good faith. We'll act in good faith.
Good-faith research under this policy is authorized — we will not pursue legal action.
We acknowledge within 2 business days and assign a severity and owner.
We aim to remediate and coordinate public disclosure within 90 days.
Paid for what you find.
Rewards scale with impact, validated against CVSS and real-world exploitability.