Report a vulnerability
Email security@endshields.com. It helps if you include:
- What you found and where: the URL, or the app version and platform.
- Steps to reproduce it.
- What an attacker could do with it.
Please don't access or change other people's data, disrupt the service, or publish the details before we've had a chance to fix it. We'll confirm we've received your report and keep you updated as we work on it.
In scope
- endshields.com and its subdomains, including the customer portal.
- The EndShields desktop app for Windows and macOS.
- The EndShields monitoring agent.
Where the product stands
EndShields is pre-launch, and we'd rather you hear the rough edges from us. The desktop app installers aren't code-signed yet, so Windows and macOS will warn you when you open one. Signing them is part of our hardening before public release.
What the app sends off your device, and who can see it, is set out in what leaves your device.
Machine-readable contact
Our contact details are also published at /.well-known/security.txt, following RFC 9116.