Coordinated Disclosure · ISO/IEC 29147 & ISO/IEC 30111
We are a research institute, not a vendor chasing customers. We perform root level code analysis on publicly distributed software and disclose what we find - to the company, and to the regulator, at the same time. Here is what that means in practice, and why it holds up. We publish what we do; the specific techniques behind any single finding stay in the report we send the company, not on this page.
Root level code analysis. Regulators in CC on every submission - national DPA + EDPS. 90-day coordinated disclosure. Our framework. Our timeline.
We do not operate bug bounty programs, HackerOne, or any third-party vulnerability reward platforms. All findings are published under Forschungsfreiheitsgesetz (Art. 17 StGG) and constitute free scientific knowledge sharing within the EU research framework - independent of commercial incentive.
Disclosure is unconditional. Every organization on our ledger receives identical treatment - same embargo, same publication, same regulator notification - whether or not they engage RFI-IRFOS commercially.
90-day coordinated embargo from initial notification to public disclosure. Regulators (DSB, EDPB, CERT.at) notified in parallel — not after the fact, not only "if this goes nowhere." Extensions considered case-by-case, for genuine remediation in progress, never for stalling.
We spend most of our time finding the things other companies didn't want found. Fair's fair — here's how to find one in ours. Real institute, real street address in Graz, Austria, no bug-bounty theater, no chatbot standing between you and the person who actually reads this.
E-Mail: rfi.irfos@gmail.com
PGP key available on request. We acknowledge all reports within 48 hours — from a human, not a ticket number.
ISO/IEC 30111 triage: reproduce it, scope it, fix it, credit you. No finding gets buried because it's inconvenient — that's the entire complaint we file against everyone else, and we're not exempting ourselves from it.
Lawful basis only. We accept findings obtained through publicly accessible information, your own devices, or software you're authorized to test — the same standard our own root-level code analysis holds to. If what you send us shows evidence of unauthorized access to a system you don't control, we do not publish or credit it under this program. We report it directly to the relevant authorities, the same way we'd expect to be treated if the roles were reversed.
Credit, your choice. Full name, alias, or fully anonymous — exactly as set out in our terms. No call, no meeting. Everything stays written, same as every disclosure we send.
rfi-irfos.com · ternlang.com · lighthouse-rfi-irfos.fly.dev · github.com/rfi-irfos/*
Social engineering, physical attacks, DoS/DDoS. We do not operate a bug bounty program — no points, no swag, no leaderboard. This isn't a platform, it's an inbox.
Responsible reporters credited publicly (with consent) in our disclosure reports. Your name, where it's earned — nothing gamified about it.
Good-faith security research conducted in line with this policy, reported to us privately and given reasonable time to be triaged, will not trigger a civil or criminal complaint from us. We will not treat your report as unauthorized access, we will treat it as the thing it is.
Because a research institute that discloses other people's undocumented tracking mechanisms, hardcoded keys, and pre-consent SDK inits, while not publishing its own security policy, would be exactly the kind of double standard we call out in our own reports. This page exists so nobody has to take that on faith either.
We work out of Graz, Austria — closer to the Alps than to a glass tower. We follow ISO/IEC 29147 to the letter, we file with regulators before anyone makes us, and we still think most corporate security pages read like they were written by the incident they're supposed to prevent. This one wasn't.