← RETURN TO FIELD DOSSIER
DIRECTIVE // HL-SEC-001
STATUS: ENFORCING
COORDINATED DISCLOSURE

SECURITY DIRECTIVE

VULNERABILITY DISCLOSURE & DEFENSIVE REPORTING

01. COMMITMENT TO DEFENSIVE INTEGRITY

HELIOS is built to provide control planes for autonomous systems. We consider defensibility and transparency foundational. We actively encourage responsible reporting of any security vulnerabilities or intake flaws identified across our web infrastructure and codebase.

02. REPORTING PROTOCOL

If you discover a potential vulnerability, please report it directly to the maintainer:

Security Contact: satvikndxd@gmail.com
Subject Line: [HELIOS SECURITY DISCLOSURE] <Short Description>
Security.txt: /.well-known/security.txt

Include a reproduction trace, potential impact assessment, and affected endpoints or source files. We commit to acknowledging reports within 48 hours.

03. SAFE HARBOR GUIDELINES

We consider research conducted in good faith under this policy to be authorized. When investigating vulnerabilities:

  • Do not access or attempt to access private applicant data.
  • Do not execute denial-of-service or volumetric spam attacks.
  • Do not extort or publicly disclose issues before coordinated remediation.
  • Give the maintainer reasonable time to deploy a patch before public disclosure.
DOCUMENT // HL-SEC-001RFC 9116 COMPLIANTHELIOS SYSTEMS