We’re upgrading our email infrastructure — for immediate response, email andrewjgaber@gmail.com meanwhile.
Skip to main content

Security Researcher Hall of Fame

Public acknowledgment of researchers who have reported valid vulnerabilities in Digital Empire products via our coordinated-disclosure policy. A finding earns a listing here after: (1) we confirm it, (2) we ship a fix, (3) we record the fix commit SHA, and (4) the researcher consents to public credit. Every row below is independently verifiable via the fix commit SHA.

Zero acknowledgments to date.

This page is honest: we have received zero externally-reported, confirmed, in-scope, resolved vulnerabilities as of today. Be the first. Full policy and submission form at /security-disclosure.

We do not pad this page with fabricated names, we do not list internal findings as if they were external, and we do not list "best-practice" notes. A name here means a real researcher found a real bug we shipped, and there is a commit SHA anyone can verify.

Grateful, always

Every vulnerability report -- confirmed or not, in-scope or not -- represents a researcher who chose to spend their time helping us improve the security of a product other people depend on, when they could have done anything else with that time. We recognize that. Even a report that turns out to be out-of-scope or a duplicate is a favor, and we treat it that way.

If you have reported a finding and prefer not to appear here (or appear only as a handle, or with a specific link back to your write-up), just tell us when you report -- the form has a "Public handle" field for exactly this. We default to explicit consent, not opt-out.

Full policy: /security-disclosure | RFC 9116 contact: /.well-known/security.txt | Digital Empire Holdings LLC