Ethics
newt lab publishes research about vulnerabilities we discover. We do so because the field of information security advances through shared knowledge, and because the public interest in secure systems is better served by disclosure than by silence. This page carries the policies that bind that work: how and when we disclose what we find, and who we will and will not work for. Every clause has a stable anchor — hover a heading to copy a link to the exact clause.
Vulnerability disclosure policy
This policy applies to all vulnerabilities discovered by newt lab researchers in software, firmware, hardware, or services operated by third parties.
Summary
- 90 + 30 days. We give vendors 90 days to ship a fix. We will extend by up to 30 additional days if the vendor is making substantive progress toward a patch. After the combined window, we publish.
- 7 days for in-the-wild exploitation. If we discover a vulnerability being actively exploited against real users, we will publish within 7 days. Protecting users at risk supersedes vendor preference.
- We publish whether the vendor asks us to or not. We coordinate when we can.
The 90-day window
When we report a vulnerability to a vendor or project, the 90-day disclosure clock starts on the day we deliver the technical report. On day 91, we publish our writeup regardless of the patch status — unless the criteria for an extension (below) are met.
During the 90 days, we will:
- Acknowledge technical questions from the vendor within two business days.
- Coordinate on the fix approach when asked.
- Share drafts of our public writeup with the vendor at least 7 days before publication, to give them the opportunity to correct technical inaccuracies or request minor redactions for user safety (not for vendor embarrassment).
- Refrain from public discussion or demonstration until publication.
The 30-day extension
We will extend the disclosure window by up to 30 days — a combined maximum of 120 days — if, and only if, the vendor provides a credible timeline showing that:
- A patch is under active development or in testing.
- The extension reflects a technical requirement of the fix, not an administrative or marketing constraint.
- A specific target date for patch availability falls within the extension window.
We do not grant repeated extensions. We do not grant extensions for bugs that have been public on any channel, nor for bugs already being exploited.
The 7-day in-the-wild policy
If we discover a vulnerability being actively exploited against real users — or if we are given credible evidence of such exploitation by a third party — we will publish within 7 days of the earlier of: (a) our confirmation of the in-the-wild status, or (b) our report to the vendor. The shorter window reflects the reality that every day of silence during active exploitation is a day of measurable harm to users.
We will coordinate with the vendor on mitigation during those 7 days where possible. We will not delay publication past day 7 at vendor request.
What we publish
A newt lab disclosure writeup will, at minimum:
- Identify the affected product, version range, and attack preconditions.
- Describe the vulnerability with enough technical detail for other researchers to reason about the class of bug and for defenders to build detection and mitigation.
- State the disclosure timeline: dates of report, acknowledgment, fix, and publication.
- Credit the original reporter and any collaborators.
- Link the CVE assignment if one was reserved.
We may withhold specific exploitation detail where publishing it would provide direct operational uplift to harmful actors without a corresponding defensive benefit. When we withhold detail, we will say so in the writeup.
Attribution and credit
We credit everyone who contributed to the discovery — internal researchers by name, external collaborators at their request, vendor engineers who worked on the fix where they wish to be acknowledged. We do not anonymize credit to protect newt lab’s narrative.
Scope and limits
This policy governs vulnerabilities we discover in third-party software, firmware, hardware, or services. It does not govern:
- Engagements we perform under contract, where the client’s disclosure posture governs; we will negotiate disclosure terms at engagement time, and we retain the right to decline engagements whose disclosure terms conflict with this policy.
- Vulnerabilities reported to us about our own tooling or website, which are handled under a separate responsible-disclosure process linked from our contact page.
Review cadence
This policy is reviewed annually, and updated in response to specific events that reveal a gap. Updates are published in-place with a visible changelog.
Questions or disclosure reports about this policy or specific vulnerabilities: see the contact page.
Client-selection and ethics policy
Offensive-security work is powerful. Research that helps a vendor fix a vulnerability before anyone is hurt is the same research, in principle, that an attacker uses to hurt people. Which of those two outcomes the work serves depends on who the work is done for, and under what terms.
This policy is the public version of how we decide who we work with. It exists in public because we want to be held to it — by our clients, by our peers, by readers who encounter our research and want to understand whose side we are on. It applies to every engagement newt lab enters into, every partnership, every sponsored research contract.
Who we will work with
- Enterprises, non-profit organizations, and public-sector agencies that want to understand and remediate vulnerabilities in systems they operate or build.
- Democratic governments and their agencies, where the purpose of the engagement is defensive — securing critical infrastructure, protecting their own citizens and institutions.
- Academic researchers and public-interest organizations.
- Vendors and open-source projects asking us to audit specific products or components.
Who we will not work with
We will not knowingly accept engagements with, or sell capabilities to, organizations in the following categories. The categories are stated broadly by design — they describe patterns of use, not specific named entities.
Targeted surveillance vendors
Organizations whose primary business is building offensive tooling sold to third parties for the surveillance of individuals. This includes vendors of so-called “lawful intercept” products where the customer base includes governments credibly documented to target journalists, human-rights defenders, lawyers, political dissidents, or civil-society organizations.
Offensive-capability brokers
Organizations whose business model is the resale of vulnerabilities, exploits, or capabilities to undisclosed customers, particularly where customer vetting is absent or opaque.
State actors with documented patterns of human-rights abuse
Where credible public reporting from independent human-rights organizations (for example, but not limited to, Amnesty International, Human Rights Watch, the UN Office of the High Commissioner for Human Rights, Citizen Lab, Access Now) documents that the prospective client has directed surveillance, detention, or violence against its own population or foreign civil-society targets, we will not accept the engagement. This applies regardless of the nominal purpose of the specific work.
Entities whose primary product is material harm to civil society
Including but not limited to: industries built on targeted harassment, non-consensual intimate-imagery platforms, and entities subject to credible public reporting of large-scale civilian harm.
Engagements whose terms would violate our disclosure policy
Including non-disclosure requirements that would prevent us from warning affected users of active exploitation, or from ever publishing the research. See the disclosure policy.
How we decide when the case is not obvious
The categories above describe the easy cases. Many real-world engagements are harder: a government agency with mixed documented behavior; a dual-use product; a contract whose stated purpose is defensive but whose underlying context is ambiguous.
For cases that are not obvious, we apply the following process:
- Surfacing. Any newt lab researcher can flag an engagement under consideration. Flagging does not require evidence — a reasoned concern is enough to trigger review.
- Review. The engagement is reviewed by the research team, with explicit consideration of the categories above, the public record of the prospective client, and the specific scope of the work. The review is minuted.
- Decision. Decisions to accept contested engagements require affirmative consensus, not merely absence of objection. A single researcher’s principled objection is sufficient to decline.
- Transparency, where possible. Where a declined engagement is public in some other venue — for example, an RFP we formally responded to — we will, to the extent possible without breaching confidentiality, note the decline publicly, and the category under which it falls.
How we disclose engagements we accept
We do not publish a complete client list. Confidentiality is a legitimate term of many engagements, and we will respect it. We do commit to:
- Disclosing, at engagement time, any newt lab researchers whose prior work creates a specific conflict of interest.
- Declining engagements that require us to publish false or misleading statements about our work or the client’s security posture.
- Publishing aggregate information about the composition of our engagement book — sectors served, proportions, regional distribution — on a regular cadence, so that our practice can be evaluated against this policy in aggregate even when specific engagements are confidential.
How this policy is revised
Annually, and also in response to specific events that reveal gaps. The policy is versioned; prior versions remain publicly accessible. We log each revision with the reason for the change.
Questions
Send correspondence about this policy to the address on the contact page. We read all of it. We do not always reply, but we do read it, and this policy has been sharpened by external correspondence in the past and will continue to be.
This policy draws on prior published ethics statements by academic and industry labs. It is newt lab’s own; it binds only newt lab. We offer it as one example of how an offensive-security firm can be explicit about these questions, in the hope that the norm in the industry shifts toward explicitness.