Reporting
Report vulnerabilities to info@blackunicorn.tech with "SECURITY" in the subject line. Include reproduction steps and impact; we read every report.
Report vulnerabilities to info@blackunicorn.tech with "SECURITY" in the subject line. Include reproduction steps and impact; we read every report.
In scope: *.blackunicorn.tech, bonklm.com, runelm.com, dojolm.com, and our published products (DojoLM, BonkLM, RuneLM, Basileak). Out of scope: bucc.blackunicorn.tech (production operations platform, not open for testing), social engineering against our staff, DoS/DDoS, physical access, third-party services we do not operate.
Good-faith research under this policy is authorised. We will not pursue legal action against researchers who comply with scope, do not exfiltrate data, and give us 90 days before public disclosure.
Acknowledgement: 48 hours. Triage: 5 business days. Fix or mitigation plan: 30 days for critical, 90 for high, best-effort for the rest.
Researchers who responsibly disclose are credited in release notes unless they request anonymity.
MFA everywhere, hardware keys for privileged access, segregated prod/dev environments, and tested backups.