Report a Security Vulnerability

Data security is of utmost priority to Recorded Future. To both thank all the contributions made by researchers to keep our user and company data safe, Recorded Future maintains a vulnerability reporting program. If you have discovered a vulnerability in our service, we appreciate your help in disclosing it to us in a responsible manner.

In simple words: We don’t shoot the messenger.

That being said, to stay on our nice side, do not alter or destroy any Recorded Future data and refrain from exploiting any security issue you may discover.

Scope of Vulnerability Reporting Program

Any vulnerability that could negatively impact confidential data discovered in a Recorded Future application, API, or content found on recordedfuture.com or any associated domains will be eligible for inclusion in the program. Any research or testing that might affect the availability, or degrade the performance, of Recorded Future's services is strictly prohibited.

How to Report an Issue

If you believe you have found a security flaw in our software, please contact security [at] recordedfuture [dot] com. We ask you do not publicly disclose suspected vulnerabilities until we have confirmed a fix is available.

Please include your preferred contact method, and enough details to allow us to efficiently reproduce the issue. You can use our PGP public key (below) to encrypt your communications to us.

Contact us if you have any questions about our responsible disclosure policy, or refer to this paper for general information about best practices for security researchers.

Response and Recognition

We will investigate and get back to you as soon as possible, usually within one business day. If you are interested in helping find the solution, let us know and we’ll involve you as much as we can.

To acknowledge the first person who alerts us to a previously unknown and non-trivial security issue, we show our appreciation by adding their name to the Acknowledgments section on this page, and offer them a snappy Recorded Future T-shirt.

We'll ask you for:

  • Your name, website, and handle as you'd like it displayed on this page.
  • Your shipping address and T-shirt size.

Acknowledgements

We thank these people and organizations for making our service more secure:

PGP Key

-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v1

mQENBFPsrvIBCAC68zAxTyZwrMK7RNTQEMfBNVHYB9RuLDVEiSXwFTPJ7dnXAmYO
RVRDYyBLm/cMem70o7HWqYW4GkHISMz1PlGGTlYv0wAbDlp5ZzxlqVdnMnn+hj34
cF06T8mkBtRm1sYuZ+v6YjImy2j3Ycy+9qTgWEWeP2g9+dOHB/TQq2gJAd7GuOzb
RBYJHIzJgXMuIXU3EkruSdwA485nGBsFrSmh4zHVPi9rk4amBSIe4sKlEpQ0bus6
mDm0tF5QfL96qDVC24ma+EGXOeekImSi81j9JLDM+LHdmY9atab6hSfByUkqOwcj
ovbYhMqcX3GQW04ssUZkrJxu4lAOYxXsWUmPABEBAAG0NlJlY29yZGVkIEZ1dHVy
ZSBTZWN1cml0eSA8c2VjdXJpdHlAcmVjb3JkZWRmdXR1cmUuY29tPokBOAQTAQIA
IgUCU+yu8gIbAwYLCQgHAwIGFQgCCQoLBBYCAwECHgECF4AACgkQ5uJ9w6Jn2nrC
Swf9FhJlOkBxky4uJS6x4TcZZxfW82DaSTxChnfxbQ9r39rkbcWXAqnwx/0dghHE
RaLdbKsGo0Cl7g8DnPvu4Vsu2aW46RQRjLJX6XXVRuJILrYr4uBfnP2vzF1Xs57e
fJziaUXNu+v74+I61hvHEDRn+FRwF10AuTG2XOaF5j95aHcu90T8j3hE9IGTjBGo
QduU2xyRVNgxTPTiY2GQAl5WP7uGiyWrekoyjCo4yUfA9PUsJCIOJh5V9FSrfdL7
rK7OvfYEyu/8P+fdqPIFs4TxyQMWDJyzZjm7ogj1jWh2NoCqSonitdkihANywpIs
1N6Nn2chapetl7dfkWHJf29ww7kBDQRT7K7yAQgA0ISN4FnsNbW5WRgbdRke6yTY
dgsn899Er8z7szUdpJWv8eEizUdK150zBsvNAQZGOHD691c7DxEm+vOXE60ytcXN
NSx5+zsCDUVzh6q/pXIGAAkqJ6VwoGsxj1NydobGoAVEcKE0Nor1hZ6AjUFAnrvI
eHhsDV570ELIFZl2EyoDBvgOEROMsEbqQlnt86Sa+C2xX3I8G31RZ83IAd4uo+24
k6kHzSiMxsxxS9o09RxArnt1zinKM/X36/gibpmZqUeJXzus2driQqxY876YquFs
3TcH8HwACMJmKKcqPEw+0xxDgMUnh7wJhNTle/uOvkTFKAaqJHAFRmvtZglxpwAR
AQABiQEfBBgBAgAJBQJT7K7yAhsMAAoJEObifcOiZ9p6oMgH/0B862v0lzSb7qL3
+0btECbKqM2Tdqo4XnKXGkp4gWrBWh1tA0iL2GSM07hx3y/wpKmpaY2MiNdne+QM
PPITkWS7r5rYysIEYGZSlBgvd6nLR6tlsHwkU+rvSY3WMuXzCvZogaWQ4OS42sb3
jwonZg4EL17Bd1o5jkfrXTRsDyjKMRzbhpN8YJpIZZlNoj3WpekaT7ql15rCunxd
XY8rfK3rj8qTEXGVw/TekfBOovgHCtlfOjPHxX++s440Numjd2GSbTM4O7zkNE/3
GmYwFAM4BtXpwDbFCO7pPz+LD0bzlqUTwYIAMJIShIOcm59vnkgZyj8JSnu1tVZz
1Z8mHf4=
=9Oc2
-----END PGP PUBLIC KEY BLOCK-----