Scope
This public origin: static catalog, DNS/mail adjacency as they affect the brand surface. Out of scope: customer enclaves, Field Mandate fieldings, and godecode.ai (report there).
C1-15 · this origin only
Report security issues on c1bertitans.com here. This origin is not in the authorization boundary. GodCode findings go to that origin’s Trust Center. Do not merge reports. Do not send CUI.
This public origin: static catalog, DNS/mail adjacency as they affect the brand surface. Out of scope: customer enclaves, Field Mandate fieldings, and godecode.ai (report there).
securityalerts@c1bertitans.com. Canonical: /.well-known/security.txt. PGP is not published — do not invent a key. Use transport TLS.
Good-faith research that does not exfiltrate PII, CUI, or credentials, and that does not perform DoS, is welcome. We will not pursue legal action for that class of testing against this origin.
Ack within 3 business days. Status within 14. No bounty until a program exists. Acknowledgments: /threat-matrix.
This origin is not in the authorization boundary. Do not put customer telemetry, CUI, or agent outbound here. Ever.