Test the defense.
Help us improve it.
We invite corporate security teams, experienced penetration testers, and independent researchers to examine RedHawk Defense. Find the weaknesses, document what happened, and help us make the system stronger.
Nothing is authorized by this page alone. RedHawk must approve the named testers, exact hostnames and paths, test accounts, methods, source IPs, dates, request rate, concurrency, and stop contact in writing before active testing.
What we want examined
- Authentication, session expiry, token replay, revocation, and authorization boundaries using approved test accounts.
- Input handling, injection resistance, browser security, and application configuration within the written scope.
- Business logic, separation between roles, and controlled attempts to cross application boundaries.
- Detection quality: correlate the approved test timestamps with what RedHawk recorded, missed, or misclassified.
Keep the service available
- No DoS or DDoS, stress/load tests, traffic floods, amplification, resource exhaustion, or deliberate service interruption.
- No destructive changes, malware, persistence, ransomware, credential stuffing, password spraying, phishing, or social engineering.
- No testing of customers, banks, employees, personal devices, third-party services, hosting infrastructure, or neighboring tenants. A shared IP does not grant scope.
- No extraction of real customer data or secrets. Stop when minimal proof is sufficient; do not expand access, enumerate private records, or publish sensitive details.
Traffic limits and stop rules
Do not start until numeric rate and concurrency limits are agreed. Stop immediately on unexpected data access, sustained latency, increased error rates, availability impact, or a RedHawk stop request. Preserve minimal evidence, contact Operations, and wait for written clearance to resume. Do not evade throttles, blocks, or quarantine.
Security controls stay enabled. Approved testing may be logged and source IPs may appear in the public RH DEFENSE LIVE feed. Coordinate this before testing.
From request to retest
- Request authorization with your identity, organization, proposed targets, methods, source IPs, time window, and traffic limits.
- Agree on a written scope and a working stop contact. RedHawk confirms what its hosting arrangement permits before approving tests.
- Test only the approved scope, then report privately and coordinate a retest after remediation.
Request a testing window
This form prepares an email draft on your device. It does not send, upload, store, or approve your request.
You can also email operations@redhawkdefense.us. Include the details below.
Report privately. Make it reproducible.
Send the affected URL, UTC timestamps, expected versus observed behavior, minimal reproduction steps, redacted requests/responses, impact, and suggested remediation. Keep tokens, passwords, personal data, and full exploit material out of the initial email; ask Operations for an agreed secure transfer channel. Coordinate disclosure and researcher credit directly. No payment or bounty is promised unless separately agreed in writing.
operations@redhawkdefense.us · 520-759-0746
For accidental findings, stop and report without probing further. Receipt of a report does not authorize additional testing.
Evidence sets the standard
We want to know what holds up, what fails, and what we must improve. Testing this deployment establishes evidence for its exact scope and conditions. It does not certify RedHawk, prove that no vulnerabilities exist, or establish readiness for a bank-scale environment.