Skip to content

What we can evidence, and what we cannot yet.

Engagements run against published standards, under written authorisation, by certified operators. Anything on this page still awaiting confirmation is marked as such rather than estimated.

Standards applied
8
Disclosure ack.
3 working days
Public record
CTFtime verified

Certifications

Placeholder — awaiting data

Operators on this team hold industry certifications including OSCP, CPTS and CRTO, and several have long professional practice outside competition. Exact figures are pending confirmation and are deliberately left blank rather than estimated.

To publish real figures, set holders on each entry in content/trust.ts. Until then every count renders as pending; the page will not invent a number.

Methodology standards

Each standard below is applied to a specific part of the work. Naming them makes coverage arguable: you can hold a report against the guide it claims to follow.

Operational handling

  • Data handling

    Engagement data is held only as long as the engagement and its retest require, then destroyed on a schedule agreed in the contract. Reports are delivered over an encrypted channel.

  • Rules of engagement

    Every engagement runs under a written authorisation naming the in-scope assets, the testing window, prohibited techniques, and the escalation path for anything that risks availability.

  • Insurance and contracting

    PLACEHOLDER — professional indemnity and liability cover details are pending. Contracting entity and terms are supplied during scoping.

  • Confidentiality

    Mutual NDA before scope is discussed in detail. We do not name clients, publish findings, or reference engagements without written permission.

Coordinated disclosure

Found something in our own estate? Tell us. We acknowledge within 3 working days and work to a 90 days from acknowledgement, or an agreed extension.

In scope

  • v1olet.xyz and its subdomains
  • Repositories under github.com/v1oletSec

Out of scope

  • Findings from automated scanners without a demonstrated impact
  • Denial of service, volumetric or resource-exhaustion testing
  • Social engineering of team members
  • Missing hardening headers with no demonstrated exploit path

Report to

hello@v1olet.xyz

PLACEHOLDER — no monetary bounty programme is currently published. Credit is given in the advisory unless you ask otherwise.

Machine-readable policy: /.well-known/security.txt

References

Placeholder

PLACEHOLDER — client references are available on request during scoping, subject to the referencing client’s consent. No client is named publicly.

Public evidence available today

Competition placements are published by the organisers and indexed on CTFtime. That record is independent of anything we say about ourselves, which is why it is the evidence we lead with.