Coordinated disclosure
The study measures exposure — so it regularly sees hosts that look vulnerable or compromised. This is how it handles that responsibly.
Principles
- We observe; we do not exploit, confirm, or interact beyond loading a page a browser would.
- Individual observations are published openly, including the address, capture, service metadata, and third-party host associations described on the data page.
- We preserve conflicting, clean, stale, missing, and adverse evidence rather than presenting a third-party association as a verified vulnerability or compromise.
- Record pages are public but marked for exclusion from search-engine indexes. Operators can request correction, removal, or exclusion from future scans.
When we observe a vulnerable or compromised host
Where third-party evidence suggests a host may be exploitable, serving malware, or acting as attack infrastructure, we make a best-effort attempt to notify the responsible party — typically the network's published abuse contact or CERT — with the minimum detail needed to locate and fix it. Because reputation and CVE signals come from third-party feeds and can be wrong or stale, notifications and public records frame them as leads to verify, not confirmed compromises.
Systemic findings
If the study independently confirms a systemic issue — a widespread default credential, an exposed management interface across a product line, or a vulnerable library at scale — we follow coordinated disclosure: notify the vendor or coordinating body first, allow a standard remediation window (typically 90 days), and only then publish analysis of the confirmed issue. Unverified provider associations remain clearly labelled as such.
Reporting something to us
If a record on this site exposes information that shouldn't be public, or you believe a finding is inaccurate, contact abuse@verdantprotocol.com — a person monitors it. You can also request removal of records or exclusion from future scans via the scan-info page.
For research collaboration, dataset questions, and citation help, contact research@verdantprotocol.com.
Response targets
- Acknowledgement: within two days.
- Initial triage: within seven days when the report concerns the Observatory itself.
- Updates: when material status changes, or at least every 14 days for an active investigation.
- Record correction/removal: handled separately through the operator workflow and targeted within two days.
Please do not send secrets by ordinary email. An encrypted reporting channel and published PGP key are not currently available; this limitation will be updated when one is deployed. Reports about third-party hosts should ordinarily go to that host's operator rather than to the Observatory.