chainbreach.com
INDEPENDENT SECURITY RESEARCH DISCLOSURE ACTIVE
Responsible disclosure · good-faith research

ChainBreach

Security research for internet-facing systems.

ChainBreach is an independent security research organization focused on finding and responsibly reporting publicly exposed systems on the internet. We work with organizations to help them understand and fix real-world exposure risks — before they are exploited.

§ 01 If you received an email from us

This domain confirms the message is genuine.

If you received a message from ChainBreach, it most likely concerns a specific URL on your infrastructure that appeared to expose configuration files or other sensitive material. We are writing only to notify you, so the exposure can be closed.

FROM [email protected]

When you reply, please reference the hostname or URL from our message. We're glad to provide additional context, re-check a fix, or correct a false positive. There is nothing to pay and nothing to sign.

§ 02 What we do

We find what is already public, and tell the people who own it.

We identify internet-facing misconfigurations — such as publicly accessible environment files, debug endpoints, and other sensitive paths — and notify the organizations that operate those systems.

Our goal is practical risk reduction, not publicity or exploitation. The exposure of one organization is rarely an isolated event; we study how these systems are discovered and abused in the wild, including by automated credential-harvesting operations.

SCOPE Exposed env & config files
Debug & status endpoints
Unprotected sensitive paths
Broad classes of public exposure

METHOD Standard HTTP verification only.
Nothing beyond what is already publicly reachable.
§ 03 How we operate

Four principles, without exception.

01

Responsible disclosure only

We report the public URL and the nature of the exposure. We do not publish, sell, or misuse credentials.

02

Good-faith contact

Outreach is aimed at security, IT, or appropriate public contact channels — never at causing alarm.

03

No unauthorized access

Our checks are limited to what is already publicly reachable, for example standard HTTP verification.

04

Coordination welcome

We're happy to provide additional context, re-check fixes, or adjust our reporting if something is a false positive.

§ 04 What we are not

Not law enforcementWe hold no authority and make no legal claims.

Not a bug-bounty platformThere is no program to enroll in and no portal to log into.

Not an extortion serviceWe never demand payment. There is no fee, ever.

Not affiliated with your vendorsUnless explicitly stated in our message to you.

§ 05 Contact

One inbox. Plain replies. We read every one.

For responses to a specific report, reference the hostname or URL from our message. If you believe a finding is incorrect, tell us — we will re-check.