BrokenIntent

Legal

Responsible Disclosure

Last updated: June 11, 2026

We spend our days reporting vulnerabilities to other companies, so we hold ourselves to the standard we ask of them. If you believe you have found a security issue in our systems, we want to hear about it — and we will treat you the way we wish every vendor treated us.

How to report

Email hello@brokenintent.com with the subject line “Vulnerability disclosure”. Include what you found, where, steps to reproduce, and the potential impact. We will acknowledge your report within 2 business days and keep you updated as we triage and fix.

Scope

  • In scope: brokenintent.com and its subdomains, including the free scanner and its APIs.
  • Out of scope: systems belonging to our clients or third-party services we use (report those to their owners), social engineering of our team, physical attacks, and denial of service.

Guidelines

  • Act in good faith: test only to the extent needed to demonstrate the issue.
  • Do not access, modify, or exfiltrate data that is not yours — proof of access is enough.
  • No availability impact: do not run denial-of-service or volumetric attacks.
  • Do not publicly disclose the issue before we have had a reasonable window to fix it (we aim for far less than 90 days).
  • One issue per report; chained findings welcome with the chain explained.

What we generally will not action

  • Reports from automated scanners without a demonstrated impact
  • Missing security headers or cookie flags on non-sensitive responses
  • SPF/DKIM/DMARC configuration opinions without a working spoofing scenario
  • Clickjacking on pages with no sensitive action
  • Version disclosure without an exploitable path

Safe harbor

If you make a good-faith effort to follow this policy, we will not pursue legal action against you or report you to law enforcement for your research. We will work with you, credit you if you want credit, and say thank you like we mean it — because we do.

Recognition

We do not currently run a paid bounty program. With your permission, we acknowledge meaningful reports publicly, and researchers who impress us tend to end up in our hiring pipeline.