Security
Last updated 11 August 2026
How we protect your business data
You’re handing us a list of the businesses you watch. That list is
commercially sensitive, and in the white label programme it is your client book.
Here is exactly how it is handled.
- Encrypted in transit. All traffic runs over TLS 1.3.
- Encrypted backups. Database backups are GPG-encrypted on our
server before they are uploaded anywhere, so the storage provider
never holds readable data.
- We don’t sell or share it. Your business list and your
briefs are not sold, rented, or shared with other customers.
- It doesn’t live forever. Retention limits are enforced
automatically on a schedule, not by hand — and you can delete your
account and its data at any time.
- What we monitor is public. The intel in your briefs comes from
publicly available sources. We do not access anything private belonging to the
businesses you track.
Full detail on what we collect, why, and how long we keep it is in the
Privacy Policy.
Questions we haven’t answered here? Ask us — we’d rather
answer than have you guess.
Report a vulnerability
If you have found a vulnerability that affects our service or our customers' data,
we want to hear about it — and we'd rather hear about it from you than find out
the hard way.
How to report
Email info@myintelbrief.com
with “Security” in the subject line.
Please include enough detail for us to reproduce and verify the issue:
- The affected URL, endpoint, or page
- Step-by-step reproduction instructions
- What an attacker could actually do with it (the impact)
- Any supporting evidence — a request/response, screenshot, or short log excerpt
Our policy
-
We do not pay bounties. We have no paid bug-bounty programme and no
budget for one. We will not negotiate a payment in exchange for the details of a
report. If that is a dealbreaker for you, please don't spend your time — we'd rather
be straightforward about it up front than waste yours.
-
We will not respond to reports that withhold the finding. A message
saying a vulnerability exists but declining to describe it until we reply, agree to
terms, or discuss compensation is not a security report, and we won't engage with it.
Send the details or don't send anything.
-
We read every report that includes reproduction steps, and we
investigate the ones that check out. We're a small team, so we don't guarantee a
response time, and we may not reply to reports we can't reproduce or that describe
no real impact.
-
Credit, if you want it. If you report something real and you'd like
to be acknowledged publicly, tell us and we'll be glad to name you once it's fixed.
What we consider out of scope
Automated scanner output with no demonstrated impact is generally not actionable for us.
That includes, unless you can show a concrete exploit:
- Missing or “weak” HTTP security headers
- SPF / DKIM / DMARC configuration opinions
- Missing rate limits with no demonstrated abuse
- Software version fingerprinting, banner grabbing, or “outdated library” reports without a working exploit
- Self-XSS, clickjacking on pages with no sensitive action, or issues requiring a fully compromised device
- Denial of service, volumetric testing, or anything that degrades service for real users
Testing boundaries
Please test only against your own account and your own data. Do not access, modify, or
retain another customer's information; do not run denial-of-service or load tests; and
do not use social engineering against our staff or our customers. If you encounter
someone else's personal data during testing, stop, don't save it, and tell us what
happened. We won't pursue action against anyone who follows these boundaries and reports
in good faith.