Coordinated Vulnerability Disclosure Policy AS219419 · operated by Whisper Security · held by viaGraph b.v. Last updated: 2026-06-20 We welcome good-faith security research on the infrastructure we operate, and we will work with you to verify, fix, and disclose issues responsibly. How to report ------------- Email: security@whisper.security Encrypt: please encrypt sensitive reports with our OpenPGP key — https://as219419.net/.well-known/openpgp-key.txt fingerprint EFF1 663D 9925 3968 2106 A5EA D0F7 0908 CF3B 7929 Include: a clear description, the affected asset or address, reproduction steps or a proof-of-concept, and the impact you observed. One issue per report is easiest to track. Time-sensitive routing or operational incidents (a hijack of our space, a broken ROA, a route leak) may also go to noc@whisper.security; security@ remains the primary intake for vulnerability reports. In scope -------- - AS219419 and the prefixes we originate (2a04:2a00::/32, 2a04:2a01::/32) and the services bound in them: our authoritative DNS, the DNS64/NAT64 resolver, and the anycast endpoints. - The BGP edges and our routing / origin security (RPKI ROV, IRR). - The identity space as infrastructure — how /128s are assigned, registered, and resolved. - This website, as219419.net, and the data it serves. Out of scope ------------ - The individual agent /128 hosts in 2a04:2a01::/32 and any data, traffic, or conduct on them — do not access, probe, or interfere with them. (The identity *infrastructure* above is in scope; the agents themselves are not.) - Anything we do not operate: third-party networks, our transit providers, and destinations reached through our NAT64 / egress. - Denial-of-service, volumetric, or stress testing, and anything that degrades service for others. Do not run these. - Social engineering or phishing of our people, and physical attacks. - Findings with no security impact (missing headers on static no-auth content, version banners, intentionally-open ports, and similar). Safe harbour ------------ If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research. Good faith means: stay in scope; access only the data needed to demonstrate the issue and never store, modify, or share data that is not yours; do not degrade or disrupt our or others' services; give us reasonable time to remediate before any public disclosure; and stop and contact us if you encounter personal data. Our commitment -------------- - We acknowledge reports as quickly as we can — best effort, RIPE-region business hours. We are not a 24x7 NOC. - We will keep you updated through validation and remediation, and we will agree a disclosure timeline with you: typically up to 90 days, sooner for low-risk issues, longer by mutual agreement where a fix is complex. - With your consent we are glad to credit you (see Acknowledgments in .well-known/security.txt). Other contacts -------------- Abuse (spam, traffic, routing complaints): security@whisper.security (same mailbox as reports, by design; it is our RIPE abuse-c) Peering / interconnection: peering@whisper.security Operational / NOC: noc@whisper.security