SECURITY

Blackbox Systems security.

Security documentation separates the public product surface, vulnerability reporting and explicitly authorized active testing.

Public product surface

The Blackbox public site is a deterministic static export served through Cloudflare Pages with declared security headers and a published security.txt contact route.

Vulnerability reporting

Suspected vulnerabilities can be reported to security@mediatorsolutions.io. Reporting a suspected issue does not authorize active testing, access-control bypass or collection of unrelated data.

Authorized testing

Active security validation requires written scope, authority over the named targets, permitted methods, operating windows, stop conditions, evidence handling and Rules of Engagement.

Findings and retest

Technical findings preserve reproduction conditions and evidence needed for review. Retest is performed against the defined finding and agreed remediation rather than treated as a broad certification.