Security
Vulnerability Disclosure
We break into systems for a living. If you find a way into ours, we want to hear it first.
Last updated: August 2026 · machine-readable copy at /.well-known/security.txt
1. How to report
Email ryan@ghosts.lk. Put the affected host in the subject line. Include the steps to reproduce, the impact as you understand it, and any proof of concept. Screenshots and request/response pairs help; a full exploit chain is not required. If you need to send something sensitive, say so in a first email and we will agree a channel before you send it.
2. What we commit to
- An acknowledgement within one business day, from a person, not an autoresponder.
- Triage and a severity call within five business days, with our reasoning.
- A fix timeline in the same reply, and a note when the fix ships.
- Credit by name or handle on this page if you want it, once the issue is closed.
- No legal action against research that follows this policy in good faith.
We do not run a paid bounty programme at the moment. We say that plainly rather than imply otherwise.
3. In scope
- ghosts.lk and www.ghosts.lk (this site and its API routes under /api/)
- account.ghosts.lk (sign-in and the customer portal)
- store.ghosts.lk (checkout)
- mail.ghosts.lk (our mail surface)
- matrix.ghosts.lk (our homeserver)
- mcp.wyrm.ghosts.lk (the hosted Wyrm connector)
4. Out of scope
- Third-party services we use but do not operate (Stripe, Cloudflare, Formspree, GitHub, cal.com)
- Denial of service, resource exhaustion, or anything that degrades a service for other users
- Social engineering of our people, physical attacks, or attacks on our personal devices
- Findings from automated scanners with no demonstrated impact
- Missing best-practice headers or configuration with no concrete exploit path
- Clients' systems that we test under contract: those have their own scope and rules
5. What we ask of you
- Test only against the hosts listed above, and only with accounts you own.
- Stop at proof. Do not read, modify, or exfiltrate data that is not yours; one record is enough to show impact.
- Do not degrade the service for anyone else, and do not use automated scanning at a rate that would.
- Give us a reasonable window to fix before anything is published. Ninety days is our default; we will ask for less if we can ship sooner.
- Comply with the law where you are. This policy is our commitment; it cannot override a statute.
6. Safe harbour
Research conducted in line with this policy is authorised by Ghost Protocol (Pvt) Ltd for the hosts in scope. We will not pursue legal action or a law-enforcement complaint against you for it, and if a third party does, we will make it known that your research was authorised here. If you are unsure whether something is covered, ask before you test.
7. Our own testing
The same rules bind us. Penetration tests we deliver for clients run under a written scope and the client’s authorisation, never against a host we have not been engaged to test. That is the line this page draws on both sides.
