I write and run production software. Security work here means defending the systems I'm responsible for. It is not a separate product and I'm not a penetration testing firm.
| System | Whose it is | Authorization |
|---|---|---|
| My own servers, this site and its mail | Mine | I own and operate them |
| SirenStack, a creator platform that takes card payments through a third party processor | Mine | I own and operate it |
| Client websites and software | The client's | Written engagement, limited to the site or system named in it |
I keep hardware for radio, RFID and embedded work. It gets used on my own devices and my own network.
I don't test, probe or scan for vulnerabilities on any system without written permission from whoever owns it.
When I email a business about a broken website, what I found came from loading their public pages the way a browser does and looking at what came back. No login attempts, no guessing at hidden pages, no exploitation. If the fix involves anything deeper than that, it happens after they've hired me and said so in writing.
If you've found a security problem in something I run, email james@ironjackholdings.com. I'll reply the same day. The machine readable version of this is at /.well-known/security.txt.