Review status
Defensive policy reviewed locally; secure reporting channel and counsel approval pending.
Scope
Coverage prioritises affected systems, evidence, mitigations, detection, patches and responsible disclosure. We do not publish credential theft, persistence, monitoring-evasion, safety-control-bypass or weaponisation instructions.
Disclosure
Potential vulnerabilities are reported privately through the manufacturer’s published channel before detailed public discussion. Publication timing considers remediation, user protection and credible evidence.
Research conduct
No testing is performed against systems without authorisation. Safety-critical equipment must never be placed at risk for reporting. Sensitive reports require a monitored, protected channel before launch.
Reference guidance