Liberty Security Services Liberty Security Services AS21990Autonomous System

Policy

Vulnerability Disclosure Policy

Liberty Security Services, LLC — AS21990

Liberty Security Services welcomes reports of security vulnerabilities in the network infrastructure we operate. This policy explains what is in scope, how to report, and what you can expect from us.

How to report

Email security reports to noc@as21990.net, or use the contacts listed in security.txt.

Please include enough detail for us to reproduce the issue: affected address or hostname, the behaviour observed, and the steps that produced it. If the finding is time-sensitive or being actively exploited, say so in the subject line.

We accept reports in English.

What we commit to

Acknowledge your reportWithin 2 business days
Initial assessmentWithin 5 business days
Progress updatesAt least every 10 business days while open
CreditOn request, once the issue is resolved

Business days are Monday to Friday, excluding U.S. federal holidays. Our NOC operates 07:00–21:00 Eastern.

We do not operate a paid bug bounty and cannot offer financial rewards.

Scope

In scope

Out of scope

What we ask of you

Safe harbour

If you make a good-faith effort to comply with this policy, we will not pursue or support legal action against you in relation to your research, and we will make it known that your actions were authorised if a third party raises the question.

This is our commitment and not a statement of law. It does not bind third parties, and it does not apply to conduct outside this policy.