Abstract illustration of responsible vulnerability research

Responsible vulnerability research

Bug bounty, practiced with care

For years, we have taken part in authorized bug-bounty programs: researching within published scope, documenting findings carefully, and reporting them through the right channels.

Active across established research platforms

Our authorized bug-bounty and competitive-security work includes participation on Immunefi, Cantina, Sherlock, and Code4rena. Responsible submissions have received acknowledgements or platform credit; we keep the focus on the work itself, not public totals.

What we do

Authorized research within published scope

We study only targets that are explicitly included in a program’s rules. Every activity is guided by its scope, testing limits, reporting process, and disclosure policy.

Abstract responsible disclosure lifecycle

Our approach

01

Review the program scope and rules

02

Test carefully and minimize impact

03

Validate the finding and its impact

04

Write a clear, evidence-based report

05

Respect remediation and confidentiality

Internal and defensive use

Our policy for AI-assisted security research

Advanced AI is a force multiplier for our internal, human-led vulnerability research. If approved for more cyber-capable model access, our use would remain limited to legitimate, defensive work on systems we own or are explicitly authorized to test.

  • Use is limited to authorized vulnerability identification, validation, code analysis, and responsible report preparation.
  • Access remains internal to authorized Landmark Software LLC users and is never provided, embedded, routed, resold, or exposed to customers or other third parties.
  • A human researcher reviews scope, validates every material finding, controls testing, and submits reports through the program’s approved channel.
  • We do not use AI for unauthorized access, credential theft, data exfiltration, malware deployment, social engineering, evasion, lateral movement, disruption, or denial of service.
  • We minimize exposure of personal and sensitive data and respect each program’s confidentiality and coordinated-disclosure requirements.
  • Use of OpenAI services must comply with OpenAI Usage Policies, cyber-abuse restrictions, and any approved access conditions.

Our principles

  • Authorization comes before testing.
  • We minimize impact and protect user privacy.
  • Reports are precise, reproducible, and evidence-led.
  • We follow coordinated disclosure and program requirements.
  • We respect confidentiality throughout remediation.

Clear boundaries

What this is not

  • We do not provide external security audits.
  • We do not offer penetration testing or security consulting.
  • We do not test systems outside explicitly authorized programs.
  • We do not disclose findings contrary to program rules.

A practice built on trust

Bug bounty research is an ongoing discipline of curiosity, restraint, and responsible communication. This page explains our approach; it is not an offer of security services.

This research activity is operated by Landmark Software LLC through Intelligence Artificielle Maroc.

Landmark Software LLC30 N Gould St Ste RSheridan, WY 82801