newt lab

Ethics

newt lab publishes research about vulnerabilities we discover. We do so because the field of information security advances through shared knowledge, and because the public interest in secure systems is better served by disclosure than by silence. This page carries the policies that bind that work: how and when we disclose what we find, and who we will and will not work for. Every clause has a stable anchor — hover a heading to copy a link to the exact clause.

Vulnerability disclosure policy

This policy applies to all vulnerabilities discovered by newt lab researchers in software, firmware, hardware, or services operated by third parties.

Summary

The 90-day window

When we report a vulnerability to a vendor or project, the 90-day disclosure clock starts on the day we deliver the technical report. On day 91, we publish our writeup regardless of the patch status — unless the criteria for an extension (below) are met.

During the 90 days, we will:

The 30-day extension

We will extend the disclosure window by up to 30 days — a combined maximum of 120 days — if, and only if, the vendor provides a credible timeline showing that:

  1. A patch is under active development or in testing.
  2. The extension reflects a technical requirement of the fix, not an administrative or marketing constraint.
  3. A specific target date for patch availability falls within the extension window.

We do not grant repeated extensions. We do not grant extensions for bugs that have been public on any channel, nor for bugs already being exploited.

The 7-day in-the-wild policy

If we discover a vulnerability being actively exploited against real users — or if we are given credible evidence of such exploitation by a third party — we will publish within 7 days of the earlier of: (a) our confirmation of the in-the-wild status, or (b) our report to the vendor. The shorter window reflects the reality that every day of silence during active exploitation is a day of measurable harm to users.

We will coordinate with the vendor on mitigation during those 7 days where possible. We will not delay publication past day 7 at vendor request.

What we publish

A newt lab disclosure writeup will, at minimum:

We may withhold specific exploitation detail where publishing it would provide direct operational uplift to harmful actors without a corresponding defensive benefit. When we withhold detail, we will say so in the writeup.

Attribution and credit

We credit everyone who contributed to the discovery — internal researchers by name, external collaborators at their request, vendor engineers who worked on the fix where they wish to be acknowledged. We do not anonymize credit to protect newt lab’s narrative.

Scope and limits

This policy governs vulnerabilities we discover in third-party software, firmware, hardware, or services. It does not govern:

Review cadence

This policy is reviewed annually, and updated in response to specific events that reveal a gap. Updates are published in-place with a visible changelog.

Questions or disclosure reports about this policy or specific vulnerabilities: see the contact page.

Client-selection and ethics policy

Offensive-security work is powerful. Research that helps a vendor fix a vulnerability before anyone is hurt is the same research, in principle, that an attacker uses to hurt people. Which of those two outcomes the work serves depends on who the work is done for, and under what terms.

This policy is the public version of how we decide who we work with. It exists in public because we want to be held to it — by our clients, by our peers, by readers who encounter our research and want to understand whose side we are on. It applies to every engagement newt lab enters into, every partnership, every sponsored research contract.

Who we will work with

Who we will not work with

We will not knowingly accept engagements with, or sell capabilities to, organizations in the following categories. The categories are stated broadly by design — they describe patterns of use, not specific named entities.

Targeted surveillance vendors

Organizations whose primary business is building offensive tooling sold to third parties for the surveillance of individuals. This includes vendors of so-called “lawful intercept” products where the customer base includes governments credibly documented to target journalists, human-rights defenders, lawyers, political dissidents, or civil-society organizations.

Offensive-capability brokers

Organizations whose business model is the resale of vulnerabilities, exploits, or capabilities to undisclosed customers, particularly where customer vetting is absent or opaque.

State actors with documented patterns of human-rights abuse

Where credible public reporting from independent human-rights organizations (for example, but not limited to, Amnesty International, Human Rights Watch, the UN Office of the High Commissioner for Human Rights, Citizen Lab, Access Now) documents that the prospective client has directed surveillance, detention, or violence against its own population or foreign civil-society targets, we will not accept the engagement. This applies regardless of the nominal purpose of the specific work.

Entities whose primary product is material harm to civil society

Including but not limited to: industries built on targeted harassment, non-consensual intimate-imagery platforms, and entities subject to credible public reporting of large-scale civilian harm.

Engagements whose terms would violate our disclosure policy

Including non-disclosure requirements that would prevent us from warning affected users of active exploitation, or from ever publishing the research. See the disclosure policy.

How we decide when the case is not obvious

The categories above describe the easy cases. Many real-world engagements are harder: a government agency with mixed documented behavior; a dual-use product; a contract whose stated purpose is defensive but whose underlying context is ambiguous.

For cases that are not obvious, we apply the following process:

  1. Surfacing. Any newt lab researcher can flag an engagement under consideration. Flagging does not require evidence — a reasoned concern is enough to trigger review.
  2. Review. The engagement is reviewed by the research team, with explicit consideration of the categories above, the public record of the prospective client, and the specific scope of the work. The review is minuted.
  3. Decision. Decisions to accept contested engagements require affirmative consensus, not merely absence of objection. A single researcher’s principled objection is sufficient to decline.
  4. Transparency, where possible. Where a declined engagement is public in some other venue — for example, an RFP we formally responded to — we will, to the extent possible without breaching confidentiality, note the decline publicly, and the category under which it falls.

How we disclose engagements we accept

We do not publish a complete client list. Confidentiality is a legitimate term of many engagements, and we will respect it. We do commit to:

How this policy is revised

Annually, and also in response to specific events that reveal gaps. The policy is versioned; prior versions remain publicly accessible. We log each revision with the reason for the change.

Questions

Send correspondence about this policy to the address on the contact page. We read all of it. We do not always reply, but we do read it, and this policy has been sharpened by external correspondence in the past and will continue to be.

This policy draws on prior published ethics statements by academic and industry labs. It is newt lab’s own; it binds only newt lab. We offer it as one example of how an offensive-security firm can be explicit about these questions, in the hope that the norm in the industry shifts toward explicitness.