Security · Vulnerability Disclosure

We'd rather hear it from you first.

GhostNet Academy runs a live, gamified training platform. If you find a real flaw in it, here's how to tell us safely — and what happens after you do.

Program: open Response target: 72h Safe harbor: yes

In scope

  • ghostnetacademy.com and subdomains
  • The GhostNet training platform — terminal, missions, GHOSTFACE feed
  • Account, session, and payment-adjacent flows
  • APIs backing the above

Out of scope

  • Denial-of-service or load testing
  • Social engineering of staff or students
  • Physical access attempts
  • Spam, phishing, or high-volume scanning
  • Third-party services we don't control

How to report

Email [email protected] with a clear description, steps to reproduce, and impact. A screenshot or short clip helps — please avoid touching real student data beyond what's needed to demonstrate the issue.

Safe harbor

Good-faith research within this scope, without accessing other students' data beyond proof-of-concept, won't be treated as a violation. We won't refer it to authorities or take action against you.

Report a finding

Recognition

Researchers who report a valid issue are credited on our Hall of Fame — unless you'd rather stay anonymous, just say so in your report.