Security Policy

Coordinated Disclosure · ISO/IEC 29147 & ISO/IEC 30111

Our Method

We are a research institute, not a vendor chasing customers. We perform root level code analysis on publicly distributed software and disclose what we find - to the company, and to the regulator, at the same time. Here is what that means in practice, and why it holds up. We publish what we do; the specific techniques behind any single finding stay in the report we send the company, not on this page.

  • Free, unconditional disclosure. Public disclosure is Tier 1. It happens after the 90-day embargo, regardless of payment, regardless of reply. Nothing is held back for money.
  • Coordinated, not cold outreach. We follow ISO/IEC 29147. Supervisory authorities are CC'd from day one - visibly, not blind-copied, not informed only if things go nowhere.
  • Evidence, not allegation. Every finding points to a specific artifact in the software as actually shipped - a declared permission, a compiled SDK class, a hardcoded key. Any competent third party can independently verify it.
  • Not-for-profit, by structure. RFI-IRFOS is a registered not-for-profit. There are no shareholders; surplus is reinvested into research. Paid advisory tiers are optional and separate - never a condition of free disclosure.
  • Research, not extortion. Our work is grounded in the freedom of scientific research (Art. 17 Austrian Federal Constitution) and GDPR Art. 89. We report on companies' own distributed software - never private, stolen, or unauthorized-access data.
  • No disruption, ever. No denial-of-service, no load testing. Findings come from static analysis of the software as shipped, never from attacking it in production.
  • No dynamic testing without an agreement, no social engineering. Live calls against a company's own systems happen only under a signed engagement. We never phish, pretext, or manipulate staff to obtain access.
  • No fabricated progress, not even from our own tools. Every in-house agentic tool runs under a written truth policy: never claim a file exists, code ran, or a test passed unless it was actually verified.

Our Disclosure Framework

Root level code analysis. Regulators in CC on every submission - national DPA + EDPS. 90-day coordinated disclosure. Our framework. Our timeline.

We do not operate bug bounty programs, HackerOne, or any third-party vulnerability reward platforms. All findings are published under Forschungsfreiheitsgesetz (Art. 17 StGG) and constitute free scientific knowledge sharing within the EU research framework - independent of commercial incentive.

Disclosure is unconditional. Every organization on our ledger receives identical treatment - same embargo, same publication, same regulator notification - whether or not they engage RFI-IRFOS commercially.

90-day coordinated embargo from initial notification to public disclosure. Regulators (DSB, EDPB, CERT.at) notified in parallel — not after the fact, not only "if this goes nowhere." Extensions considered case-by-case, for genuine remediation in progress, never for stalling.

We spend most of our time finding the things other companies didn't want found. Fair's fair — here's how to find one in ours. Real institute, real street address in Graz, Austria, no bug-bounty theater, no chatbot standing between you and the person who actually reads this.

Reporting a Vulnerability

E-Mail: rfi.irfos@gmail.com
PGP key available on request. We acknowledge all reports within 48 hours — from a human, not a ticket number.

How We Handle What You Send Us

ISO/IEC 30111 triage: reproduce it, scope it, fix it, credit you. No finding gets buried because it's inconvenient — that's the entire complaint we file against everyone else, and we're not exempting ourselves from it.

Lawful basis only. We accept findings obtained through publicly accessible information, your own devices, or software you're authorized to test — the same standard our own root-level code analysis holds to. If what you send us shows evidence of unauthorized access to a system you don't control, we do not publish or credit it under this program. We report it directly to the relevant authorities, the same way we'd expect to be treated if the roles were reversed.

Credit, your choice. Full name, alias, or fully anonymous — exactly as set out in our terms. No call, no meeting. Everything stays written, same as every disclosure we send.

Scope

rfi-irfos.com · ternlang.com · lighthouse-rfi-irfos.fly.dev · github.com/rfi-irfos/*

Out of Scope

Social engineering, physical attacks, DoS/DDoS. We do not operate a bug bounty program — no points, no swag, no leaderboard. This isn't a platform, it's an inbox.

Hall of Fame

Responsible reporters credited publicly (with consent) in our disclosure reports. Your name, where it's earned — nothing gamified about it.

Safe Harbor

Good-faith security research conducted in line with this policy, reported to us privately and given reasonable time to be triaged, will not trigger a civil or criminal complaint from us. We will not treat your report as unauthorized access, we will treat it as the thing it is.

Why We Publish This Page At All

Because a research institute that discloses other people's undocumented tracking mechanisms, hardcoded keys, and pre-consent SDK inits, while not publishing its own security policy, would be exactly the kind of double standard we call out in our own reports. This page exists so nobody has to take that on faith either.

A Word on Tone

We work out of Graz, Austria — closer to the Alps than to a glass tower. We follow ISO/IEC 29147 to the letter, we file with regulators before anyone makes us, and we still think most corporate security pages read like they were written by the incident they're supposed to prevent. This one wasn't.

RFI-IRFOS  ·  ZVR 1015608684  ·  GISA 39261441  ·  GLN 9110038490191  ·  UID ATU83405245  ·  Steuernummer 68 696/8736  ·  Elisabethinergasse 25/10, 8020 Graz